Back to skill

Security audit

social-persona-profiling

Security checks for vulnerabilities and agentic risk

Overview

This skill is not technically malicious, but it asks an agent to make speculative psychological profiles and relationship/work guidance about other people from limited social traces.

Install only if you are comfortable with a skill that analyzes personal traces about other people. Use it for low-stakes reflection or scam-safety triage, avoid minors and non-consenting private individuals where possible, and do not use its output for hiring, retaliation, public accusations, relationship-ending decisions, diagnoses, or manipulation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation scope is broad enough to solicit profiling of colleagues, dates, friends, or strangers from limited social traces, which can enable privacy-invasive inference, unconsented psychological profiling, and manipulative relationship guidance. Although the skill includes warnings, it still operationalizes sensitive trait inference and relationship attribution in everyday scenarios where users may act on speculative conclusions about non-consenting third parties.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file presents all guidance in Chinese and does not indicate that the user can opt into another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file says social-trace analysis should only produce tentative hypotheses, but then uses observed mismatch between self-presentation and behavior as a basis for inferring emotional distress risk and deficient self-awareness. In a skill explicitly designed to profile strangers, dates, and colleagues from limited online signals, that contradiction can encourage ungrounded mental-health style judgments that users may over-trust and act on.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

Although the text correctly warns that attachment inference from avatars or chat records has very low validity, it still operationalizes those same traces to infer closeness strategies and relationship tendencies. In the context of a profiling skill for interpersonal decision-making, users may collapse that nuance and treat speculative attachment-style readings as reliable guidance about another person's motives or suitability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The output format mandates fixed English section headings and report structure, while the file does not state that users may choose their preferred language for responses. This can violate a language/locale policy when a skill imposes a language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This markdown file presents all instructions and content exclusively in Chinese, and nowhere indicates that the user can opt into another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.