Back to skill

Security audit

Confession Coach Skill

Security checks across malware telemetry and agentic risk

Overview

The coaching skill itself is narrowly scoped, but its bundled publish script points to a different ClawHub identity and could publish the wrong package if run.

Use the coaching instructions only for relationship advice and avoid sharing more personal detail than needed. Do not run publish.sh unless you intentionally want to publish to the ReplyHer target and have verified the repository, slug, account, and changelog first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The publish script claims to release the current skill, but the actual ClawHub slug and printed repository URLs point to a different project identity (`replyher`) rather than `confession-coach`. This can cause maintainers to publish the wrong artifact to another skill listing or repository namespace, leading to accidental overwrite, supply-chain confusion, or release of unintended content under the wrong identity.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The comments and usage text describe this as a generic publish script for this skill, but the concrete destination is another project. That mismatch is dangerous because it misleads operators into trusting the script and increases the chance of accidental cross-project publication, especially in one-command release workflows.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The README states the skill 'activates automatically when you need it' without defining clear triggers, scope, or limits. Overly broad activation language can cause the agent to invoke the skill in unintended contexts, leading to inappropriate handling of unrelated user inputs or unnecessary exposure of sensitive relationship-related disclosures.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.