Back to skill

Security audit

Entp Coach

Security checks for vulnerabilities and agentic risk

Overview

This coaching skill is not malicious, but it needs review because it mixes ENTP and INTP materials and instructs the agent to keep personal coaching records without clear consent or deletion controls.

Install only if you are comfortable with an ENTP coaching skill that currently contains INTP documentation drift and may retain personal self-development notes across sessions. Before use, ask the publisher to align ENTP/INTP materials and add clear opt-in, review, and delete controls for any saved coaching profile.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The README consistently presents this as an INTP coaching skill, while the manifest metadata says the skill is for ENTP users. This mismatch can cause the agent/router or reviewers to misunderstand who the skill targets, leading to incorrect activation, misaligned guidance, and weakened trust in the declared behavior of the package. In a personality-targeted coaching skill, identity and trigger scope are core safety boundaries, so documentation drift is materially risky rather than a cosmetic issue.

Description-Behavior Mismatch

Medium
Confidence
86% confidence
Finding
The documented examples and behavior broaden use beyond the manifest's explicit requirement that the user clearly state they are ENTP. Phrases like generic '分析瘫痪了' and '专注力太分散了' describe activation paths that could trigger for non-ENTP users, causing the skill to engage outside its declared audience and deliver personality-specific advice based on an incorrect assumption. In a coaching context, this can produce misleading or inappropriate guidance, though it is less severe than direct code execution or data exfiltration.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The manifest metadata is materially inconsistent with the stated purpose of the skill: it is named and described as an ENTP coach, but the keywords and tags identify INTP. Identity mismatches in package metadata can cause the wrong skill to be surfaced, reviewed, or trusted, and they increase the chance that users receive guidance not intended for their context. In a coaching skill, this matters because the output is persona-sensitive and misleading metadata undermines safe routing and user expectations.

Description-Behavior Mismatch

Low
Confidence
92% confidence
Finding
The repository URL points to an apparently unrelated project, which breaks provenance and makes it difficult to verify the source, maintenance history, and intent of the skill. While not directly exploitable like code execution, misleading provenance can conceal supply-chain substitution, frustrate auditing, and reduce trust in the artifact. In this context, a coaching skill is lower impact than a privileged automation skill, but the mismatch still increases review and integrity risk.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The reference file is entirely about INTP coaching while the skill is declared as ENTP-only, creating a clear scope and persona mismatch. In a coaching agent, this can cause systematically incorrect guidance to users who explicitly identify as ENTP, undermining trust and potentially producing harmful personal, career, or learning advice based on the wrong behavioral model.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The documentation explicitly labels the file as 'INTP Coach' reference material and states its purpose is for an INTP Coach skill, directly contradicting the declared ENTP coach intent. This strengthens evidence that the skill may operationally rely on the wrong persona model, making misguidance likely rather than incidental.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill says it will keep '成长记录' and save conversation and action data for later use, but it does not provide a clear user-facing notice or consent step. In a coaching context, those records can include sensitive personal goals, emotional struggles, and behavioral patterns, so silent retention creates privacy and trust risks.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The '用户档案' and '存档' sections define cross-session retention of personal coaching data without a clear warning to the user. Because the stored content includes problems, insights, plans, and execution history, this can accumulate into a meaningful behavioral profile that users may not expect to persist.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs retention of user conversation/profile data for future sessions, which increases the risk of unnecessary persistence of sensitive personal information. In a coaching setting, even non-financial details can reveal mental state, life direction, habits, and vulnerabilities, making accidental disclosure or misuse more harmful.

Ssd 3

Medium
Confidence
95% confidence
Finding
Repeated instructions to store user interests, insights, and action history normalize broad memory collection without clear limits. That creates a natural-language data leakage risk because later responses may surface prior sensitive details unexpectedly or retain more information than needed for the immediate task.

Ssd 3

Medium
Confidence
97% confidence
Finding
The described 'user dossier' includes behavioral patterns, interests, goals, and execution history for future use, which is exactly the sort of cumulative profile that heightens privacy risk. In context, this is more dangerous because coaching conversations often surface intimate self-assessments and recurring weaknesses that could be exposed later.

Ssd 3

Medium
Confidence
96% confidence
Finding
Making user-archive maintenance a mandatory rule encourages systematic retention whether or not it is necessary for the conversation. This increases the chance that sensitive coaching content will persist beyond user expectations and be reused or exposed in later interactions.

Ssd 3

Medium
Confidence
97% confidence
Finding
The conversation-close workflow instructs the agent to archive user problems, insights, plans, and later outcomes for future recall, creating a durable record of sensitive self-development data. This is risky because the end-of-session archival step is operationalized as routine behavior, yet no consent, minimization, or retention controls are defined.

Static analysis

No suspicious patterns detected.