Back to skill

Security audit

AI Life Coach

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed life-coaching prompt skill with broad emotional triggers, but it does not run code, access files, persist data, or hide unrelated behavior.

Install this only if you want a Chinese-language life-coaching assistant that may activate on broad emotional phrases. It should not be treated as therapy or crisis care, and users discussing self-harm or ongoing distress should seek qualified professional or emergency support.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

High
Confidence
96% confidence
Finding
The skill declares automatic activation for broad emotional-language matches and explicitly instructs the system to switch personas without explicit user invocation. In a sensitive mental-health-adjacent context, this can cause unintended interception of ordinary conversations, override expected assistant behavior, and initiate crisis-style probing based on ambiguous text.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The metadata trigger list contains many generic phrases such as sadness, confusion, or wanting to talk, which are common in unrelated conversations. This increases the chance of accidental activation and misclassification of user intent, especially because the skill operates in a high-sensitivity emotional-support domain.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
90% confidence
Finding
The single-word trigger '迷茫' is short and semantically broad, so it may match many benign discussions not intended as a request for coaching. Because the skill auto-activates in response to trigger-adjacent language, even a low-specificity term can produce unwanted takeover in emotionally sensitive contexts.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
90% confidence
Finding
The trigger '焦虑' is a common emotional descriptor and may appear in casual discussion, summaries, or third-party references. In a skill that can shift into counseling-like behavior, such low-specificity matching risks inappropriate activation and unnecessary safety escalation.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
90% confidence
Finding
The trigger '沮丧' is similarly generic and may capture everyday sentiment rather than a deliberate request for this skill. Given the surrounding instructions to automatically assume a coaching role, the low threshold raises the risk of mistaken routing in normal conversations.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.