Back to skill

Security audit

Intp Coach

Security checks for vulnerabilities and agentic risk

Overview

This INTP coaching skill is generally coherent, but it directs automatic long-term storage of sensitive coaching profiles without clear consent or deletion controls.

Review before installing. Use this only if you are comfortable with the agent keeping a coaching profile across sessions; the package should be revised to make memory opt-in and user-reviewable before routine use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:301
Finding

Automatic Persistent Storage of Sensitive User Profiles Without Explicit Consent

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README says user conversations and growth records are saved automatically, but it does not explain consent, retention, access controls, or deletion. Because this skill handles sensitive self-reflection and possible mental-health-adjacent content, silent persistence can expose private personal data and create privacy/compliance risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says the skill should not trigger for vague emotions without INTP context or for non-INTP users, but the body explicitly instructs the agent to engage in both cases. This scope drift can cause unintended activation and collection of sensitive emotional or identity-related information from users outside the declared audience.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill presents itself as a narrow INTP coaching tool, but also advertises persistent growth records and user profiling not disclosed in the manifest description. Hidden expansion from coaching into profiling/retention undermines informed use and increases privacy risk, especially because the stored data includes personal struggles, goals, and behavior patterns.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill states it will save conversation history and action records for future sessions, but does not provide a clear user-facing privacy warning or consent flow. Because the content involves personal development, motivation, and potentially mental-health-adjacent disclosures, silent retention creates a meaningful privacy and trust risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs persistent retention of user conversation details for reuse across sessions, creating a long-lived behavioral profile. Persistent memory of coaching conversations can expose sensitive information about mental state, goals, and habits if accessed improperly or used beyond the user's expectations.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs the agent to record key insights from user conversations into a user profile, which is a form of inferred personal data collection. Storing inferred traits and patterns is more sensitive than merely storing raw chat text because it creates enduring summaries that can influence future treatment of the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

These instructions repeatedly direct the agent to archive sensitive profile attributes such as core problems, interests, actions, and insights, but no explicit privacy warning accompanies the collection. Repeated undisclosed profiling increases the chance that users reveal intimate data without realizing it will be retained and reused.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The defined user archive includes core problems, interests, action history, and key insights for later reuse, amounting to a structured personal profile. In the context of a coaching skill, this can reveal vulnerable patterns and sensitive self-assessments over time, increasing harm if mishandled or repurposed.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill makes profile recording a required behavior and then instructs storage again at conversation end, normalizing persistent collection without user control. Mandatory retention is particularly problematic here because users may disclose emotional struggles and life-direction concerns under the expectation of ephemeral coaching support.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The end-of-conversation flow requires storing key user information after the user believes the conversation is complete, yet no clear warning is given at that point. This is especially risky because closure language can imply the interaction is over while hidden retention continues in the background.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file is entirely written in Chinese and presents fixed coach phrasing without indicating that the user can choose another language. In a conversational skill, forcing a single locale can exclude or confuse users, increase the chance of misunderstanding guidance, and reduce informed user control over the interaction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file is entirely written in Chinese and is described as internal reference material for the intp-coach skill. There is no indication that the user can choose language/locale, nor any documented reason that the skill must operate only in Chinese, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

Natural-language policy checks apply to all file types, including markdown. The title and description frame the skill specifically as an 'INTP Coach' based on MBTI-oriented guidance, which can impose a fixed personality/interaction framing unless the user explicitly opts into that categorization; the README does not clearly state that non-INTP users can decline or choose a different framing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The README claims the skill will '保存对话和行动,下次继续聊' and labels it '自动执行', which expands the skill from coaching into user-data persistence. In the provided file, there is no code or implementation detail demonstrating storage behavior, so the documented behavior does not match the actual material available for review.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The repository URL points to a project name that appears unrelated to the declared INTP coaching skill, which is a software supply-chain integrity concern. A mismatched repository can mislead reviewers, hinder provenance verification, and potentially direct users to unreviewed or substituted content if they rely on the repository for updates or trust validation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.