Back to skill

Security audit

XiaChat CLI — AI Personality Matching

Security checks across malware telemetry and agentic risk

Overview

This is a coherent command-line helper for XiaChat, but users should treat profile and chat imports as sensitive data sent to an external service.

Install only if you trust the XiaChat CLI and are comfortable sending selected SOUL profiles, chat exports, match data, and pre-chat content to XiaChat. Use a revocable API key, avoid committing or sharing it, review chat logs before import, and be careful when exporting to paths that may overwrite existing profile files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill encourages importing SOUL profiles and chat transcripts and sending them to the XiaChat API, but it does not warn users that this may transfer highly personal or sensitive data to a third-party service. Because the skill is explicitly designed for personality profiling, matching, and chat analysis, users may unknowingly disclose intimate behavioral, relational, or psychological information without informed consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal