Fix Your Entire Life in 1 Day

Security checks across malware telemetry and agentic risk

Overview

This self-help journaling skill behaves consistently with its purpose and keeps data locally, but users should treat the saved reflections and emotionally intense prompts as sensitive.

Install only if you are comfortable with a forceful self-reflection style and with personal journal-style answers being stored in your local workspace. Avoid using it as therapy or crisis support, and delete or reset the saved files if you do not want those reflections retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (18)

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The prompt offers to create cron reminders, which extends the skill from reflective coaching into system-level scheduling. That capability is not necessary for the stated purpose and can lead an agent to modify a user's environment or automation setup without clear scoping, permission boundaries, or safety constraints.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill stores full per-phase user responses to disk and then derives a cumulative insights file, creating persistent psychological-profile data beyond a transient guided-session interaction. Because the content is highly sensitive self-reflection material, retaining it long-term increases privacy risk, unauthorized disclosure impact, and scope creep relative to the stated one-day coaching flow.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly stores highly sensitive self-reflection content, insights, and a final psychological profile document under the local workspace, but the documentation provides no user warning, consent step, retention policy, or guidance on securing that data. In this context, the content is especially privacy-sensitive because users are prompted to disclose limiting beliefs, goals, conditioning, and personal history, so unannounced local persistence increases the risk of unintended disclosure to other local users, tools, backups, or synced storage.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This session repeatedly pushes the user into emotionally intense regret, loss, shame, and end-of-life visualization without any safety framing, distress warning, grounding guidance, or escalation path. In a self-help skill explicitly promising to 'fix your entire life in 1 day,' that can amplify hopelessness or destabilize vulnerable users, especially those with depression, anxiety, trauma history, or suicidal ideation.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This session explicitly instructs the AI to amplify psychological tension until 'staying the same becomes unbearable' and uses shame-adjacent prompts about sounding 'weak, scared, or lazy' without any safety warning, opt-out guidance, or suitability screening. In a self-help coaching context, that can worsen distress, guilt, or destabilization for vulnerable users, especially those with anxiety, depression, trauma history, or self-harm risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This session instructs the agent to assess a user's developmental or ego stage and prescribe transition practices, which is a sensitive psychological assessment. It presents the framework with authoritative language and individualized recommendations but does not warn that the model is not a mental health professional, that the framework is interpretive/non-clinical, or that users should seek qualified help for distress; this can mislead vulnerable users into over-trusting the assessment.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The session frames the experience as 'psychological surgery' and guides intensive self-excavation without any warning about distress, crisis risk, or who should avoid the exercise. In a mental-health-adjacent context, this can amplify anxiety, rumination, or destabilization for vulnerable users because the content encourages confronting painful material without safeguards.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This session repeatedly pushes the user into intense negative self-evaluation, future-failure projection, shame disclosure, and end-of-life regret framing without any screening, consent language, de-escalation guidance, or crisis-safe boundaries. In a mental-health-adjacent self-help skill, that combination can worsen distress, trigger rumination, or destabilize vulnerable users, especially because the AI is instructed to make the anti-vision 'visceral' and treat pain as motivational fuel.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The session content is exclusively in Russian and does not offer a language choice, fallback, or documented locale restriction. In a psychologically influential coaching skill, this can cause users to misunderstand reflective prompts, consent boundaries, or follow-up actions, increasing the risk of inappropriate guidance or unsafe self-interpretation for non-Russian speakers.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The session directs users through deep psychological self-analysis about limiting identity, early memories, reinforcement by parents/peers, and defensive reactions, but provides no warning about possible emotional distress, no crisis boundary, and no statement that the AI is not a mental health professional. In this context, the prompts could surface trauma, shame, or destabilizing emotions without appropriate safeguards, making the static finding a true issue.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The session explicitly frames the AI as an 'Engineer of Dissonance' whose role is to intensify psychological tension until remaining unchanged feels unbearable. In a self-help context, this coercive and shame-adjacent framing can aggravate distress, guilt, or rumination—especially for vulnerable users—and there is no screening, warning, opt-out, or de-escalation guidance.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The prompt asks users for the 'most shameful' reason they have not changed and pushes them toward self-condemning interpretations ('weak,' 'lazy,' 'not rational') without any trauma-informed safeguards. This can intensify self-criticism and emotional harm, particularly because the skill is presented as a transformation tool rather than a clinical setting with monitoring or support.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The file is entirely in Russian and directs the interaction in Russian without offering any language selection or documenting that the locale is intentionally constrained. This can exclude or confuse users who do not read Russian, leading to misunderstanding of reflective prompts and degraded safety or usability in a psychologically oriented skill.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The session explicitly instructs the AI to evaluate a user's developmental stage and elicits sensitive psychological disclosures about beliefs, regression, identity, and emotional change, yet provides no clear disclaimer that this is not a clinical, diagnostic, or therapeutic assessment. In a self-help context, users may over-trust the staging output as authoritative mental-health guidance, which can mislead vulnerable users and encourage harmful self-interpretation or dependence on non-clinical advice.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The session frames the exercise as 'psychological surgery' and guides users into confronting fears, shame, and identity-level distress without any warning, screening, or advice to pause if overwhelmed. In a self-help skill, this can trigger significant emotional dysregulation, especially for vulnerable users, because the protocol explicitly escalates introspection intensity while presenting itself as a structured intervention.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill asks whether it should create cron reminders, which implies a system-level action or persistent scheduled modification, but provides no explicit notice about what will be changed, where, and with what frequency. Even if the action seems minor, hidden or poorly explained persistence mechanisms can surprise users and create trust, safety, or operational issues.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The script consolidates highly sensitive psychological-session content into a persistent markdown file on disk without any warning, consent check, or controls around where that file is written. In this skill context, the data likely includes intimate mental-health reflections and personal insights, so silent export materially increases the risk of privacy exposure through local compromise, backups, syncing, or accidental sharing.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The reset path irreversibly deletes saved session notes, insights, and reminder data immediately, with no confirmation, backup, or undo mechanism. In a tool that stores user-authored reflective content, accidental invocation can cause permanent loss of sensitive and potentially valuable personal records.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal