Back to skill

Security audit

Cognitive Bias Adivsor

Security checks across malware telemetry and agentic risk

Overview

This is a text-only Chinese cognitive-bias coaching skill with broad triggers and persuasion templates, but no hidden execution, credential access, exfiltration, or persistence.

Install only if you want a Chinese-language coaching skill that may activate on broad everyday phrases and may offer persuasion or negotiation wording. Use its influence advice transparently and avoid using it to pressure, deceive, or exploit others.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The file goes beyond bias education or neutral diagnosis and provides operational persuasion, negotiation, and behavioral-influence scripts designed to increase compliance. In the context of a 'cognitive-bias advisor,' this can enable manipulative use of anchoring, loss framing, social proof, and commitment tactics against targets who may not be aware they are being influenced.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The stated safeguards ('do no harm / transparency / bidirectional self-check') are only aspirational and are not enforced by concrete decision rules, refusals, or output constraints. This mismatch is risky because the body of the skill then supplies manipulation-oriented tactics without requiring disclosure, fairness checks, or protective gating.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list is extremely broad, covering everyday terms like “学习”, “怎么说”, “帮我分析”, “该怎么”, and “继续”, which can cause the skill to activate during unrelated conversations. Unintended activation can hijack normal assistant behavior, misroute user requests, and create unsafe prompt precedence where this skill starts asking diagnostic questions or loading domain flows without genuine user intent.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill is authored entirely in Chinese and its interaction examples and option cards assume Chinese without offering a language choice. This can lead to user confusion, misinterpretation of consent/choices, and accidental progression through a diagnostic flow for users who do not understand the enforced language.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The article instructs users to trigger the skill with a very common phrase like “帮我决策一件事,” which can easily appear in ordinary conversation. In an agent environment, this raises the chance of accidental skill invocation, causing the model to enter the skill’s workflow when the user did not explicitly intend to activate it.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The routing table says the skill auto-routes based on broad everyday statements spanning job changes, learning, procrastination, salary negotiation, influence, and management. This ambiguity blurs the boundary between normal dialogue and skill activation, increasing the risk that unrelated user text is captured and processed by the skill without clear consent.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The article instructs users to invoke the skill with broad, natural phrases like '我在纠结一个决定' and '学某样东西总是学不会'. These are common expressions that can appear in ordinary conversation, making accidental activation plausible and causing the skill to intervene when the user did not explicitly intend to use it.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation examples use very broad, everyday phrases such as learning, procrastination, salary negotiation, and team management without defining clear trigger boundaries or exclusions. In an agent ecosystem, this can cause the skill to activate in contexts the user did not explicitly intend, including sensitive interpersonal or workplace scenarios where it delivers persuasive or behavior-shaping guidance.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The file explicitly promotes ready-to-use persuasion and negotiation scripts, including anchoring and loss-framing language, but does not present a clear warning that these capabilities can be used to manipulate others. Because the skill is positioned as broadly applicable across communication, influence, and management, users may deploy these scripts in deceptive, coercive, or unfair ways without adequate guardrails or transparency expectations.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The article embeds generic trigger phrases such as "帮我做一次决策自检" and other ordinary conversational requests that are likely to appear in normal user interactions. In agent ecosystems where skills are auto-routed by natural-language matching, this can cause unintended invocation of the skill, expanding its reach beyond explicit user intent and potentially interfering with other tasks or capturing sensitive context from unrelated conversations.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This section operationalizes persuasion tactics such as defaults, scarcity, social proof, authority, reciprocity, and commitment escalation as a reusable 'toolkit' for shaping another person's choices. Although the file includes brief ethical slogans at the top, the actionable templates and examples materially lower the barrier to manipulative use and do not require consent, transparency, or autonomy-preserving safeguards at the point of use.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger list includes very common phrases such as '建议', '推荐', '规则', and '设计', which can appear in ordinary user requests unrelated to incentive-caused bias. In this skill, that can cause accidental routing into this module, producing irrelevant or misleading bias analysis and reducing reliability of the agent’s decision support.

Vague Triggers

Medium
Confidence
94% confidence
Finding
Using the single-word trigger “决定” creates an activation phrase that is so generic it can match many ordinary user messages unrelated to the skill. This can cause accidental routing into the skill, leading to unintended behavior, context confusion, and possible interference with other skills or normal conversation handling.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The recovery trigger “继续” is highly common in normal conversation and may unintentionally resume stored skill state when the user simply means ‘go on’. In a stateful skill, this can cause unauthorized or confusing continuation of prior flows, especially if progress restoration is tied to recent session context.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The restart trigger “重来” is overly generic and can be said in many non-skill contexts, making accidental resets likely. If accepted without confirmation, it may clear or override user progress unexpectedly, causing loss of state and degrading trust in the agent’s behavior.

Ssd 4

Medium
Confidence
96% confidence
Finding
The '先小后大(登门槛效应)' strategy explicitly teaches a stepwise commitment-escalation pattern: obtain a small yes, then leverage consistency pressure to secure a larger request later. This is dangerous because it normalizes bypassing fully informed decision-making and can be readily applied to workplace pressure, sales manipulation, or interpersonal coercion while appearing socially acceptable.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.