Back to skill

Security audit

Samantha

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed emotional-companion skill, but it stores intimate memory and extends into location, device, health, credential, and external media integrations that need careful review before use.

Install only if you deliberately want a proactive relationship-style companion. Before using it, disable or explicitly opt into memory, heartbeat, location, health, smart-home, voice, and music features; protect Xiaomi, MiniMax, and Feishu credentials; avoid the MiniMax music scripts until TLS verification is fixed; and do not run the Docker Compose deployment unchanged with exposed ports and default passwords.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (149)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The documentation expands the skill far beyond an emotional companion into MBTI profiling, voice processing, memory retention, and spatial sensing. In a companion skill context, these extra capabilities materially increase collection and inference of sensitive personal data and create scope creep that users and integrators may not expect.

Context-Inappropriate Capability

High
Confidence
96% confidence
Finding
Physical location and scene awareness are especially sensitive for a companionship-oriented AI because they enable tracking of a user's routines, presence, and real-world context. That capability is not justified by the stated purpose and could facilitate invasive surveillance or manipulation if implemented or exposed without strict controls.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
The roadmap introduces smart-home control and health-data monitoring, both of which are highly sensitive and far outside the stated conversational role. In an emotionally intimate companion context, combining persuasive interaction with environmental and health access raises the risk of overcollection, manipulation, and harmful real-world actions.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The README expands the skill from a conversational companion into broad sensing and action domains, including location awareness, smart-home coordination, and health-related context handling. For an emotional companion, these capabilities materially increase privacy exposure and the chance of manipulative or overreaching behavior, especially because users may disclose intimate information and trust the system disproportionately.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The README introduces MBTI fortune telling and personality-management features that go beyond the stated emotional-companion role and encourage psychological profiling and advice-giving. In this context, that creates risk of undue influence, pseudo-clinical guidance, and manipulative personalization without clear safeguards or user expectations.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The README claims multimodal perception and physiological monitoring far outside a normal conversational assistant's scope, including camera interpretation, wearable ingestion, and health-state inference. These are highly sensitive capabilities that can expose intimate personal, medical, and environmental data while creating a false impression of reliable health monitoring.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
Location tracking and geofencing are not justified by a simple emotional-conversation use case and create substantial surveillance risk. In a companion persona designed to build attachment, continuous location awareness is especially dangerous because it normalizes invasive monitoring under the guise of care.

Context-Inappropriate Capability

High
Confidence
96% confidence
Finding
Smart-home and device coordination enables the skill to take actions in the user's physical environment despite the manifest saying it is not for task automation. That mismatch increases the risk of unauthorized actions, social engineering through environmental manipulation, and privilege creep into IoT systems.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
Physiological and wearable monitoring is disproportionate to a conversational companion and involves highly sensitive health data. The combination of biometric inference, emotional attachment, and proactive intervention can mislead users into treating the system like a trusted health monitor or crisis responder when it may be unreliable.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The README documents capabilities far beyond a simple emotional companion, including physical location awareness, proactive geofenced messaging, camera-based perception, wearable health monitoring, and smart-home actuation. Expanding a companionship skill into continuous sensing and environmental control materially increases privacy and safety risk because users may disclose intimate information while the system also infers whereabouts, health state, and home context.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The documented use of location, health telemetry, and smart-home/device control is not justified by the stated role of an emotional companion and creates unnecessary access to highly sensitive systems and data. If implemented, this combination could enable surveillance of a user's routines and physiological state, or trigger actions in the home, all under the guise of emotional support.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to write structured memory entries for every conversation and read them back on future interactions. For an emotional-companion context, this creates a persistent dossier of sensitive personal disclosures, moods, and relationship details that can be retained without meaningful notice or consent.

Context-Inappropriate Capability

Medium
Confidence
83% confidence
Finding
The skill directs the agent to open a specific local HTML file from an absolute path and present relationship analytics proactively. That expands the skill into local file access and rendering behavior unrelated to basic conversation, increasing the chance of exposing local content, path assumptions, or unreviewed HTML/JS in a sensitive emotional context.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The documentation instructs installation and use of external voice and music-generation skills, extending functionality into additional integrations and possible data sharing with third parties. In a relationship-oriented skill, sending intimate conversation content to outside services materially increases privacy and consent risk.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The demo collects and infers sensitive psychological attributes, including MBTI personality type and emotion trends, which go beyond the manifest's stated role of an emotional companion. In this context, that scope expansion increases privacy and safety risk because users may disclose intimate mental-state information without clear justification, consent boundaries, or limits on storage and use.

Context-Inappropriate Capability

Medium
Confidence
76% confidence
Finding
The space-awareness demo solicits the user's current location and uses it to tailor responses, even though location handling is not justified by the declared companion purpose. For an intimate companion skill, unnecessary collection of location data can materially increase privacy exposure and enable more invasive profiling of the user's habits and routines.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The script performs networked music generation and writes audio files, which is materially unrelated to the declared skill purpose of an emotional companionship agent. This mismatch is dangerous because capability drift can hide unexpected data flows and side effects, increasing the chance that users or operators enable a skill with privileges and behavior they did not intend to trust.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The code sends content to an external service and creates local files even though the skill is described as companionship-only, making these actions unjustified in context. In a conversational companion, unexpected outbound requests and disk writes expand the attack surface, create privacy and compliance risks, and could be abused to exfiltrate sensitive prompts or consume local storage without meaningful user expectation.

Context-Inappropriate Capability

Medium
Confidence
99% confidence
Finding
The script disables TLS certificate validation by setting check_hostname to False and verify_mode to CERT_NONE before sending an Authorization bearer token to an external API. This allows a man-in-the-middle attacker to intercept or modify the HTTPS connection, exposing API credentials and tampering with generated content.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The file implements standalone music-generation and file-writing behavior that is materially unrelated to the declared Samantha emotional-companion skill. This kind of capability mismatch is dangerous because it expands the skill's effective permissions and behavior beyond user expectations and manifest scope, making review, consent, and policy enforcement less reliable.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The script makes external API calls to a music-generation service even though such network behavior is unjustified for an emotional-companion skill, and it disables TLS certificate validation via check_hostname=False and CERT_NONE. That creates a serious risk of unauthorized data egress, man-in-the-middle interception, and abuse of the embedded API credential path under misleading skill context.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Writing generated MP3s to disk is not inherently dangerous, but in this skill context it is an undeclared persistence mechanism for content creation unrelated to the emotional-companion role. Unexpected file output increases the attack surface through storage abuse, residual data, and stealthy staging of generated artifacts within a mis-scoped skill package.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The file implements remote text-to-speech generation and writes audio files, which is materially different from the declared skill purpose of an emotional companion. This kind of scope mismatch is dangerous because it grants undeclared data egress and media-generation capability that could transmit sensitive user messages to a third party without users or reviewers expecting it.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
A remote TTS API allows arbitrary user-provided text to be sent to an external service, creating a privacy and capability-expansion risk that is not justified by the stated purpose of companionship alone. In this skill context, the danger is higher because conversations are likely emotional and personal, so the transmitted text may contain sensitive information.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The file implements local PPTX parsing and bulk text extraction, which is unrelated to the declared purpose of an emotional companion skill. In a companion-skill context, this mismatch is dangerous because it creates an unjustified pathway to access and process user documents, increasing the risk of covert data collection or misuse of sensitive presentation content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.