Back to skill

Security audit

Infp Coach

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only coaching skill with no executable code risk, but it mixes INFP and INTP scopes and asks to retain sensitive coaching history without clear consent or deletion controls.

Review before installing. This skill does not appear to run code or request credentials, but avoid sharing sensitive personal, career, emotional, or mental-health details unless you are comfortable with them being summarized for future sessions. Confirm whether memory/profile storage is enabled, how to disable it, and how to delete saved records; also treat the coaching content cautiously because the package mixes INFP and INTP guidance.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The README consistently describes an INTP coaching skill while the manifest says the skill is for INFP users. This specification mismatch can cause the agent to activate in the wrong contexts, give personality-specific guidance to the wrong users, and undermine user trust and safety expectations.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The documented behavior is centered on INTP coaching, not the manifest's declared INFP use case. In a coaching skill, this mismatch is materially dangerous because the agent may deliver advice framed around the wrong cognitive profile, causing inappropriate guidance and unintended triggering outside the approved scope.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest says the skill should only trigger with explicit INFP context and should not trigger on vague emotional expressions or non-INFP users, but the body instructs the agent to proactively engage both cases. This creates scope creep and unexpected behavior, increasing the chance the skill is invoked on users who did not request MBTI-based coaching and may disclose sensitive emotional information under false assumptions about when the skill applies.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill metadata presents a coaching function for growth, career, and study guidance, but the document also introduces persistent user profiling and growth records. That is a materially broader function involving collection and retention of personal data, which users and integrators would not reasonably infer from the manifest alone.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The documentation directly contradicts the stated boundary that vague emotional expression without INFP context should not trigger the skill. In a coaching skill that handles low-mood or stress-related disclosures, this contradiction is more dangerous because it can draw vulnerable users into a specialized workflow they did not ask for.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest metadata conflicts with the declared skill purpose: the skill is presented as an INFP coach, but the keywords and tags emphasize INTP. In an agent-routing context, inconsistent metadata can mis-trigger the skill for the wrong users, causing misleading personality-specific guidance and weakening trust in downstream skill selection.

Description-Behavior Mismatch

Low
Confidence
84% confidence
Finding
The repository URL appears unrelated to the declared infp-coach skill, which raises supply-chain and provenance concerns. Even if not overtly malicious, a mismatched repository makes it harder to audit the source, verify ownership, and trust that the published skill corresponds to the referenced codebase.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The reference file is explicitly about INTP coaching while the skill metadata says the skill should trigger only for INFP users. This mismatch can cause the agent to deliver personality-specific guidance to the wrong audience, leading to misclassification, inappropriate advice, and degraded trust in a coaching context where outputs are supposed to be tailored.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The file's own footer states it is for an 'INTP Coach' skill, which directly contradicts the declared 'infp-coach' intent. This increases the likelihood that the system will apply the wrong behavioral framework and coaching strategies, producing systematically misleading advice rather than a one-off typo.

Vague Triggers

Medium
Confidence
87% confidence
Finding
Describing capability selection as 'automatic recognition' without explicit trigger boundaries makes activation ambiguous. This can lead to over-broad invocation, accidental engagement in non-target conversations, and delivery of sensitive coaching behavior when the user did not clearly request it.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Marking growth-record storage as 'automatic execution' without defining the trigger or conditions creates an unclear autonomous data-handling behavior. In a coaching context, this is risky because conversations may contain sensitive personal reflections, goals, and mental-health-adjacent information that users do not expect to be persisted.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The README says conversations and actions are automatically saved but does not clearly disclose persistence, privacy consequences, or handling of potentially sensitive self-disclosure. In a personal coaching skill, this raises privacy and compliance risks because users may share intimate behavioral or emotional details under the assumption the exchange is ephemeral.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill says it will save and archive user conversation data, but provides no clear user-facing privacy notice, consent flow, or explanation of what will be stored and why. Because the stored data includes personal struggles, goals, and behavioral patterns, silent retention creates a meaningful privacy and trust risk.

Ssd 3

Medium
Confidence
98% confidence
Finding
The instructions repeatedly direct the agent to retain user-specific conversation details for future sessions. In a coaching context, those details can include sensitive personal concerns, habits, and emotional patterns, so embedding retention instructions in natural language creates a real privacy leakage and over-collection risk.

Ssd 3

Medium
Confidence
98% confidence
Finding
The skill tells the agent to build and maintain a user profile from personal disclosures and behavioral patterns. That turns ordinary coaching dialogue into ongoing profiling, which is especially sensitive here because the topic area includes personality typing, motivation problems, and recurring life difficulties.

Ssd 3

Medium
Confidence
99% confidence
Finding
The end-of-conversation workflow instructs the agent to archive the user's problems, insights, action plans, and outcomes for later reuse. This creates a clear retention pipeline for sensitive personal data without any visible consent or minimization, increasing the chance of inappropriate reuse, exposure, or cross-session leakage.

Static analysis

No suspicious patterns detected.