Back to skill

Security audit

Mindfulness Guide

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned, but its crisis-resource guidance should be treated as location-specific and not universal.

Before installing, confirm the skill gives crisis resources appropriate to your country or region. In an immediate emergency, use local emergency services or a local crisis line rather than relying on any single region-specific hotline listed by the skill.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The disclaimer hard-codes Beijing and national China hotline numbers without asking the user’s location or stating that these resources may only apply in China. In a crisis context, presenting region-specific emergency resources as if generally applicable can delay access to appropriate local help, especially for users outside China or in time-sensitive self-harm situations.

Static analysis

No suspicious patterns detected.