Back to skill

Security audit

论语 — 私人语录

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local personal quote archive, with privacy considerations but no evidence of hidden collection, exfiltration, or unsafe installation behavior.

Install only if you are comfortable with selected conversation snippets and surrounding context being saved locally in ~/.hermes/lunyu/. Avoid saving secrets, confidential work material, or intimate content on shared or synced devices, review entries before exporting or enabling daily notifications, and use the documented delete/edit commands to remove accidental captures.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The README states that the agent will automatically store user-provided quotes in a private collection, but it does not clearly warn that content is persisted to local files or discuss privacy implications. Users may share sensitive personal thoughts, relationship details, or intimate remarks under the assumption that the interaction is ephemeral, leading to unintended retention and later exposure.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README describes passive capture where the agent may proactively suggest saving '精彩句子' from normal conversation, but it does not warn that incidental conversational content may be flagged for recording. In this skill context, users are encouraged to speak spontaneously, which increases the chance that sensitive or embarrassing statements are surfaced and saved without clear informed consent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
被动触发条件以“特别有力量/智慧/幽默”等主观标准判断,边界不清,容易让 agent 在普通对话中误判并发起保存建议。由于该技能本身会持久化用户原话和上下文,这种模糊触发会扩大敏感内容被收集和保存的范围。

Vague Triggers

Medium
Confidence
94% confidence
Finding
使用“记”“嗯”“好”这类高频自然语言作为确认词,缺乏足够特异性,容易把普通应答误解释为同意保存。结合该技能的持久化存储行为,这会导致未经充分知情同意的语录和上下文被写入本地文件。

Missing User Warnings

Medium
Confidence
96% confidence
Finding
技能文档说明会把语录、上下文、章节等信息持久化到本地文件,并通过定时任务持续整理,但没有充分提醒这些内容可能包含隐私、敏感关系信息或长期画像数据。用户可能在不了解保留范围、保存位置和后续处理的情况下被持续收集。

Ssd 3

Medium
Confidence
97% confidence
Finding
该技能明确要求 agent 记录用户话语并“自动抓取上下文氛围”,属于对会话内容及其语境的持久化采集。上下文往往比原句更容易包含敏感个人信息、关系信息或行为线索,长期积累后会形成详细的用户画像。

Ssd 3

Medium
Confidence
95% confidence
Finding
被动触发机制鼓励 agent 主动建议保存“精彩”语句,这会在没有用户预先发出保存命令的情况下扩大收集面。对于包含情感、工作、家庭或暧昧内容的日常对话,这种设计会提高敏感信息被引导持久化的概率。

Ssd 3

Medium
Confidence
96% confidence
Finding
存储结构包含原句、上下文、章节、标签和类型,且每日编译到额外文件,形成多份持久副本并增加暴露面。随着时间推移,这些原始语录和语境注释可能泄露个人偏好、关系状态、地理迁移、工作情况及其他敏感披露。

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.