Back to skill

Security audit

PsyVector pv42

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only Chinese mediation persona with broad trigger words, but it contains no code, install behavior, credential access, persistence, or hidden data transfer.

Install this only if you want a Chinese-language mediation persona. Use it deliberately for conflict or HR scenarios, avoid sharing unnecessary confidential details, and disable or narrow automatic activation if broad trigger words like conflict, balance, or coordination would be too intrusive.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list contains broad, common terms such as “矛盾”, “冲突”, “平衡”, and “协调”, which can appear in many ordinary conversations unrelated to mediation. This can cause accidental skill activation, leading the agent to adopt a role-playing mediation persona in contexts where users did not intend it, potentially degrading response quality or interfering with higher-priority safety behavior.

Static analysis

No suspicious patterns detected.