Back to skill

Security audit

Cognitive Bias Adivsor

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese cognitive-bias coaching skill with broad conversational triggers and persuasion advice, but its behavior is disclosed, text-only, and does not request credentials, tool authority, persistence, or hidden execution.

Install only if you want a Chinese-language coaching skill that may activate on broad everyday decision, learning, communication, and management phrases. Treat its decision and persuasion output as reflective guidance, not legal, medical, financial, employment, or relationship advice, and avoid using the influence templates to pressure or mislead others.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Missing User Warnings

Low
Confidence
91% confidence
Finding
The README presents the skill as providing advice across major life domains including decision-making, influence, communication, and management, but it does not disclose limitations, uncertainty, or boundaries on use. In an agent setting, this can cause users to over-trust persuasive or behavior-shaping outputs for consequential personal or interpersonal decisions, increasing the risk of harmful guidance or manipulation.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list is extremely broad and includes generic phrases like '学习', '该怎么', '帮我分析', and '继续', which can match ordinary conversation unrelated to this skill. This can cause unsolicited activation, unintended conversation hijacking, and routing users into manipulative or sensitive guidance flows without clear intent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The article encourages invoking the skill with very common natural-language phrases such as '帮我决策一件事', and the metadata trigger list includes broad terms like '决策', '学习', '拖延', and '管理团队'. In an agent environment that routes skills based on phrase matching, such generic triggers can cause accidental activation during ordinary conversation, leading to unintended skill execution and unexpected access to user context.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The article explicitly encourages invocation through broad natural-language phrases like “我在纠结一个决定” and “学某样东西总是学不会,” which are common in ordinary conversations. In a skill that auto-intervenes based on trigger phrases, overly generic triggers can cause unintended activation, leading to unsolicited behavioral guidance or routing when the user did not intend to invoke this skill.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger examples are broad everyday phrases such as learning difficulties, procrastination, salary negotiation, and team management complaints, which can overlap with ordinary conversation and cause the skill to activate without clear user intent. In an agent setting, this can lead to unsolicited routing into persuasive or diagnostic behavior, increasing the chance of inappropriate advice or unintended manipulation-oriented outputs.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The file explicitly promotes influence techniques and ready-to-use negotiation scripts, including framing, anchoring, loss aversion, and designing choice environments, without pairing them at that point with strong safety boundaries or misuse warnings. Because the skill is positioned as a practical coach rather than a purely educational reference, users may be guided toward manipulative interpersonal tactics that can pressure, deceive, or unfairly influence others.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The article includes highly generic trigger examples such as '帮我做一次决策自检', '我项目做了两年,该不该叫停?', and '我刚学了一个新理论,帮我检验一下', which are ordinary user phrases likely to appear in many unrelated conversations. Without explicit scope constraints, invocation boundaries, or exclusions, the skill may activate unintentionally and steer the agent into this skill when the user did not intend to use it, causing routing hijack or irrelevant behavior.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill content is entirely in Chinese and provides no language choice, opt-in, or fallback, which can cause users or downstream agents to misunderstand instructions, consent prompts, and decision guidance. In a decision-support skill, language mismatch can lead to incorrect routing, skipped safeguards, or users agreeing to actions they did not fully understand.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The file is entirely written in Chinese and provides no mechanism to detect or adapt to the user's language preference, which can exclude or mislead users who do not understand the content. In an agent skill, forced locale can cause users to miss important safeguards, consent language, or manipulation-related caveats, especially in a domain about influencing others.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list includes very common conversational terms such as “建议”, “推荐”, “设计”, and “规定”, which can cause the bias module to activate for ordinary user messages that are not actually about incentive structures. In a routing-based skill, overly broad activation degrades precision, can lead to incorrect diagnostics, and may systematically steer users into irrelevant psychological framing.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The single-word trigger "决定" is overly generic and can be said in many ordinary conversations, which creates a real risk of unintended skill activation. In a conversational agent, overly broad activation can hijack unrelated user flows, cause confusing state transitions, and expose users to advice or data handling paths they did not intend to invoke.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The resume trigger "继续" is highly ambiguous because it is common in normal conversation and can easily appear outside the intended resume workflow. This can incorrectly restore prior session state or advance a diagnostic flow without explicit user intent, which is especially risky in a stateful skill that preserves progress across questions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The restart trigger "重来" is too generic and may be spoken casually in many contexts, making accidental destructive actions plausible. Because restart clears or resets conversational progress, an unintended trigger can erase user state, disrupt workflows, and undermine trust in the assistant's behavior.

Ssd 4

Medium
Confidence
97% confidence
Finding
This section explicitly teaches a foot-in-the-door influence technique: obtain a small commitment, then escalate to a larger request after the person has psychologically committed. In the context of a skill dedicated to shaping others' choices, this normalizes behavioral steering and can be used for coercive persuasion, workplace pressure, or deceptive consent engineering even though the file includes soft ethical framing elsewhere.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.