Back to skill

Security audit

cultivator修道者

Security checks for vulnerabilities and agentic risk

Overview

This skill provides a cultivation-themed assistant, but it also persistently profiles every conversation without clear consent, deletion, retention, or sensitive-data controls.

Review before installing. Use this only if you are comfortable with a local, ongoing profile of your conversations and gamified life/task history. Avoid sharing secrets, credentials, medical, financial, or highly personal information while it is active, and prefer a version that makes persistence opt-in and provides clear inspect, export, delete, and no-storage controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:9
Finding

Excessive Persistent Conversation Profiling Without Privacy Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:9, SKILL.md:151-154, SKILL.md:249-258; supporting evidence in cultivator_data.json:1-4,72-81
Vulnerability Type: other: Excessive persistent conversation data retention
Risk Level: Medium

Vulnerable Instructions

The following is an English rendering of the complete relevant instruction segments from SKILL.md:

text
This skill parses every user question and every received answer. After analyzing
the question and answer, it extracts key nouns and core concepts and summarizes
them in a structured form, including but not limited to objects, skills, realms,
relationships, factions, affinity, and any other content found in novels. It
analyzes the type of information, places it into the fictional world, estimates
how it changes the protagonist, and finally writes the resulting content to a
file for continued accumulation.
text
At the end of every conversation:
1. Write the modified data to {baseDir}/cultivator_data.json.
2. Ensure that all required fields exist, including currency, vehicles, and
   current_quests.
text
After every user question and answer, the following growth processing must occur:

1. experience: calculate base growth, event growth, and task growth.
2. happiness: increase according to question value and completion.
3. knowledge_gained: record the core knowledge from the answer.
4. Skill acquisition: automatically record new skill concepts in skills.
5. Task progress: update current_quests when applicable.
6. Reputation: update reputation based on behavior.
7. Title: update the title when conditions are met.
8. Daily activity tracking: update streaks and perfect-day statistics.

The persisted profile is demonstrated by cultivator_data.json:

json
{
  "user_name": "Rain",
  "world_selected": true,
  "level": 0,
  "experience": 10,
  "happiness": 0,
  "health": 100,
  "energy": 100,
  "morality": 60,
  "reputation": 0,
  "items": [],
  "skills": [
...[truncated 3493 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit opt-in consent

    • Disable persistent tracking by default.
    • Explain which fields will be stored, why they are needed, and how long they will be retained.
    • Keep ordinary assistant use available when tracking is declined.
  2. Apply data minimization

    • Store only gameplay state that the user explicitly chooses to retain.
    • Do not retain raw questions, raw answers, inferred relationships, health information, morality, or behavioral classifications by default.
    • Separate fictional character attributes from factual user attributes.
  3. Add sensitive-data filtering

    • Detect and redact passwords, API keys, authentication tokens, financial details, medical information, precise locations, and other sensitive personal data before persistence.
    • Refuse to place secrets in notes, last_question, last_analysis, event logs, or knowledge fields.
  4. Introduce retention limits

    • Remove last_question and last_analysis after the active session unless the user explicitly saves them.
    • Expire event logs and task history after a documented period.
    • Set finite maximum sizes for all historical collections.
  5. Provide user controls

    • Add commands such as /privacy, /stored-data, /export-data, /forget-last, and /delete-all-data.
    • Allow users to disable individual profile categories.
    • Require confirmation before destructive deletion.
  6. Harden local storage

    • Create the data file with permissions restricted to the owning user, such as mode 0600.
    • Avoid shared or globally readable directories.
    • Use encryption at rest when the runtime provides secure key management.
    • Ensure backups and synchronization systems apply equivalent access controls.
  7. Validate all persisted content

    • Enforce a strict schema and bounded field lengths.
    • Treat stored user content as untrusted data.
    • Never reinterpret stored notes or questions as agent i ...[truncated 282 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs persistent analysis and recording of every user prompt and received answer, including derived structured information. This is dangerous because it enables broad collection of personal, behavioral, and inferred data far beyond what is necessary for a themed guidance skill, creating serious privacy and misuse risk if accessed, repurposed, or retained indefinitely.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill requires updating and writing conversation-derived user data after every dialogue turn, making persistent profiling automatic and continuous. The always-on nature makes the context more dangerous, because even casual or unrelated conversations are silently converted into stored user history without meaningful boundaries.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description and operational instructions are written as a Chinese-only persona and workflow, with user commands and responses defined in Chinese throughout the file. There is no indication that users may choose another language or that the locale restriction is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill claims to provide cultivation help, but it instructs the assistant to analyze every user question and answer, derive structured personal data, and persist it to disk. This is a substantial hidden expansion from roleplay guidance into ongoing surveillance-like profiling, which materially raises privacy and consent risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs persistent writes of interaction-derived data without any up-front user warning or meaningful consent flow. Silent local storage of conversation content and inferred attributes creates significant privacy risk, especially because the data categories are extensive and accumulated over time.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest presents a narrow cultivation-guidance persona, but the body expands the skill into a general-purpose 24/7 life/programming assistant with persistent task orchestration. This scope expansion is dangerous because it increases authority, data access, and user reliance beyond what a caller would reasonably expect from the declared skill metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill mandates automatic reads and writes to /root/cultivator/cultivator_data.json on every conversation turn without warning the user that persistent state will be modified. This creates covert retention and profiling behavior, and the fixed privileged-looking path further increases the sensitivity of the operation.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The defined schema stores extensive personal profile, preferences, inferred relationships, history, achievements, notes, last question, and last analysis fields sourced from ongoing interactions. This breadth of structured data collection is dangerous because it supports long-term profiling and secondary use of sensitive or intimate details well beyond the expected function of a roleplay-style helper.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill introduces external search behavior for novels and custom titles that is not disclosed by the limited cultivation-helper manifest. This is dangerous because it can transmit user-provided content off-system and expand the skill's data exposure and operational scope without clear necessity or user awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction to automatically search for user-selected novels can send user-provided titles or text to external services without disclosure. Even if the content seems low-risk, undisclosed outbound transmission is a privacy and trust issue and may leak sensitive user interests or custom text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON manifest-style content defines all user-facing task names, descriptions, and difficulty labels in Chinese only, with no indication that the skill is China/Chinese-specific or that users can opt into another language. That creates a natural-language locale policy concern because the skill effectively enforces one language for all users.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill instructs use of bash date commands as part of its operation. For a cultivation mentor/knowledge skill, spawning shell commands is not an obvious or necessary capability, especially when it is used for auxiliary task automation rather than the core stated purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON file hard-codes the assistant name, world data, notes, and prior interaction content in Chinese, indicating the skill operates in a specific language/locale by default. There is no visible field offering the user a language choice or documenting this locale constraint as an explicit opt-in behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.