Relationship Coach

Security checks across malware telemetry and agentic risk

Overview

This is not malware, but it automatically creates lasting relationship and partner notes containing very sensitive information without enough consent or deletion guidance.

Install only if you want the agent to keep ongoing relationship notes in workspace files. Before use, decide what may be stored, review or delete generated profiles regularly, avoid storing private disclosures without explicit permission, and do not use it for abuse, coercion, self-harm risk, emergencies, or issues needing a licensed professional.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill extends a conversational coaching role into persistent cross-session memory by creating and updating detailed partner profiles, relationship dynamics, and session notes in the workspace. This is risky because it encourages durable storage of highly sensitive mental-health and relationship data without explicit consent, minimization, retention limits, or access controls, increasing privacy and misuse risk.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
Maintaining a living 'relationship agreement' file turns the assistant from a coach into a keeper of durable behavioral rules between partners. That can create undue authority, fossilize contested expectations, and store sensitive interpersonal commitments that may later be invoked out of context or in coercive ways.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger criteria are broad enough to match common everyday relationship language, which can cause the skill to activate in situations where the user did not request therapeutic-style coaching or persistent profiling. In this skill, accidental invocation is more dangerous because activation leads into sensitive emotional analysis and cross-session recordkeeping.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This file provides real-time conflict guidance for intimate partners but contains no safety boundary for situations involving abuse, coercion, threats of self-harm, or immediate danger. In a relationship-coaching skill, users may apply these cards during high-risk crises where de-escalation language is insufficient or unsafe, causing delay in seeking emergency or professional help.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This document gives detailed guidance for processing attachment injuries, betrayal, and trauma-adjacent relational wounds without an upfront warning that the material may be emotionally activating or that it is not a substitute for licensed mental health support. In a relationship-coaching skill, users may treat the content as actionable therapeutic direction and attempt high-intensity repair conversations without adequate screening, crisis awareness, or professional containment, which can worsen distress or re-trigger trauma.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal