Back to skill

Security audit

social-persona-profiling

Security checks across malware telemetry and agentic risk

Overview

This is a text-only skill for speculative social-persona analysis, with meaningful privacy and safety caveats in the core instructions but some documentation wording users should treat carefully.

Use only with concrete, consent-aware social context, and do not treat outputs as reliable psychological truth. Do not use it for hiring, credit, legal, medical, public shaming, manipulation, or decisions that materially affect another person; keep inputs minimal and avoid private third-party content when consent is absent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
README 中的示例触发语如“帮我理解这段关系 / 我接下来该怎么办?”过于日常、泛化,容易与普通聊天或求助语句重叠,导致系统在用户未明确请求该技能时被意外触发。对一个会基于有限社交痕迹输出人格判断、关系建议和可信度评估的技能来说,误触发会放大隐私、误判和不当画像风险。

Missing User Warnings

Medium
Confidence
92% confidence
Finding
技能说明强调可跨平台利用头像、聊天行为、可见性设置和分享内容进行人物侧写,但未在入口位置充分警示隐私、同意、误判、文化偏差及对第三方进行敏感推断的风险。鉴于该技能面向“同事、约会对象、朋友或陌生人”的分析场景,缺少显著风险提示会鼓励用户在未获当事人同意时进行画像,并把低质量推断当作可靠结论。

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This file operationalizes psychological profiling from social-media traces, including emotional-distress-related inference, but does not pair that guidance with an explicit privacy/sensitivity warning or clear limits on analyzing identifiable people without consent. In the context of a skill explicitly marketed for profiling colleagues, dates, friends, and strangers, that omission can normalize invasive or overconfident judgments about real people and increase misuse risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.