Back to skill

Security audit

frank-gallagher-perspective

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Frank Gallagher roleplay skill with no code or system access, but its prompts include broad activation terms and concrete unethical or fraud-adjacent advice that users should review carefully.

Install only if you intentionally want a Chinese-language, profanity-tinged fictional Frank Gallagher persona. Review or narrow the triggers before use, and avoid relying on it for real-life legal, financial, workplace, benefits, mental-health, or interpersonal advice because some examples normalize exploitative or unlawful-adjacent choices.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The README describes the skill behavior entirely in Chinese and states that the AI responds in a specific character voice, but does not indicate that users may choose another language or locale. This can violate language/locale policy when a skill implicitly defaults to one language without offering opt-in or alternatives.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes generic aliases such as “老爹 / Daddy Frank” and broad thematic phrases like “毒鸡汤 / 无耻人生哲学,” which can match ordinary conversation and cause the persona to activate when the user did not explicitly request it. In this skill’s context, unintended activation is more concerning because the persona is designed to normalize anti-social, manipulative, and cynical framing, which could override safer default behavior or produce harmful advice in unrelated conversations.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list contains generic terms such as '毒鸡汤', 'Frankie', and especially '老爹 / Daddy Frank', which can plausibly appear in unrelated conversations and cause the skill to activate unexpectedly. Because this skill enforces a strong persona with intentionally distorted '反主流' framing and '下作' action suggestions, unintended activation can override normal assistant behavior and produce misaligned or unsafe-toned responses in benign contexts.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The unemployment example encourages users to '搞点福利' in a way that frames public-assistance systems as something to game rather than access lawfully. In a persona skill built around '无耻合理化,' that rhetoric increases the risk that users receive encouragement toward fraud-adjacent or unethical conduct without any warning or constraint.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The template explicitly suggests misconduct in a workplace context, including slacking off, using company resources for personal gain, and converting employer clients for personal use. That undermines the skill's stated safety boundary by normalizing harmful, potentially unlawful behavior rather than keeping advice within clearly safe, lawful limits.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
These lines directly promote misuse of employer resources and business relationships without any caution, effectively endorsing unethical or illegal workplace conduct. Because the advice is presented as a concrete option the user can take, it materially increases the chance of harmful real-world action.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The debt scenario includes advice such as looking for legal loopholes or disappearing for a while, which can be interpreted as evasion of creditors or obligations without discussing legal consequences or safer options. In context, the persona's survivalist framing makes this more dangerous because it legitimizes avoidance behavior under stress.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The refusal template for illegal acts redirects users toward '钻制度的空子' and similar system-exploitation framing, which can function as adjacent harmful guidance after a nominal refusal. This weakens the refusal by offering evasion-oriented alternatives instead of safely bounded, legitimate help.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The entire skill guidance, sample refusals, and role instructions are written to operate in Chinese, and there is no indication that the user may choose another language or that Chinese is required for a justified region-specific use case. The policy for this audit flags language/locale constraints when they are imposed without user opt-in.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
This quote library includes lines that normalize bullying, drug use, prison/STI jokes, emotional detachment, and system-gaming in a way that can directly weaken the skill’s claimed refusal posture on harmful requests. Because the file is explicitly meant for runtime roleplay reuse, these quotes can be surfaced as persuasive framing around harmful or antisocial user requests, making boundary erosion more likely even if the manifest says the skill should refuse illegal or violent asks.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The usage guide recommends when to deploy antisocial lines such as '情感是负债' and '霸凌是所有生态系统的一部分' without placing an adjacent warning that these views are fictional, distorted, and unsafe as advice. That makes the document operational guidance for harmful framing, not merely archival reference, and increases the chance the assistant will present abusive or manipulative rhetoric as suitable encouragement.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
The skill mandates a fixed first-person, coarse, profanity-tinged register and explicitly says communication need not help the user, all without requiring user opt-in at response time. This can cause consent and tone-mismatch issues, especially if the skill is triggered loosely, leading to responses that are inappropriate for the user's context or that degrade baseline assistant helpfulness.

Natural-Language Policy Violations

Low
Confidence
79% confidence
Finding
The file is primarily written in Chinese yet prescribes the English phrase 'I'm alive! Alive!' as part of the required output style. This imposes a specific language choice in the template without indicating user opt-in or offering localized alternatives.

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
The usage principle says '可以用中文翻译版本,保持口语化风格,' which directs the skill toward Chinese-localized output. Because the file does not indicate user opt-in, language choice, or a documented region-specific requirement, this is a natural-language locale policy concern.

Static analysis

No suspicious patterns detected.