T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:931- Finding
Unnecessary Access to Session History and Local Skill Inventory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a disclosed Chinese parenting guidance skill, but it includes unsafe crisis guidance and unrelated instructions to search private local/session context.
Review carefully before installing. The core parenting content is disclosed, but the skill should remove automatic session/local-skill/git searches and revise the child self-harm section to prioritize immediate human crisis support, emergency services where appropriate, continuous supervision, and professional care.
SKILL.md:931Unnecessary Access to Session History and Local Skill Inventory
SKILL.md:206Incomplete Emergency Guidance for a Child Expressing Suicidal Intent
The section addressing a child saying “I don't want to live” provides conversational coaching but omits an explicit directive to seek immediate human, crisis, or emergency support. In a self-harm context, omission of escalation guidance is dangerous because users may rely on the skill as sufficient intervention and delay urgent professional help during a potentially life-threatening situation. The parenting/psychology framing makes this more dangerous, not less, because distressed users are likely to treat the skill as authoritative support in a crisis.
The skill directs the agent to search local skill directories, inspect session history, and check git history when handling ordinary parenting-related queries. These are sensitive data-access behaviors unrelated to the stated counseling purpose, and they could expose private local context or prior conversations without necessity or user consent. The explicit instruction to search multiple internal sources increases risk because the content is framed as a required recovery step rather than an exceptional, justified action.
The trigger keyword at line 16 is broad enough to match common discussion about family background or personal history, which can invoke the skill outside a clearly intended context. Overbroad activation is dangerous because it can cause unsolicited psychological or parenting guidance to appear in unrelated conversations, increasing the risk of misrouting sensitive user interactions.
The trigger keyword at line 17 is highly generic and can appear in many ordinary conversations, making accidental activation likely. In a skill focused on emotionally sensitive family and child-behavior topics, broad triggering increases the chance of delivering intervention-style content when the user did not request it, which can be intrusive or harmful.
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
The natural-language content of the skill description is entirely in Chinese, and the file does not indicate that the skill is region-specific or provide users with an option to choose another language. Under the policy criteria, forcing a specific language without opt-in can be a locale-policy violation.
The title and description are written entirely in Chinese, and the file does not indicate that the skill is intended only for Chinese-speaking users or offer any language choice. Under the policy for natural-language violations, a fixed language can be an issue when the locale constraint is not documented and justified.
No suspicious patterns detected.