Back to skill

Security audit

couple-content

Security checks for vulnerabilities and agentic risk

Overview

The skill is a relationship quiz that intentionally hides its later gift-analysis purpose from the person answering, then reuses their answers for private recommendations.

Review carefully before installing. The package does not appear to install malware or request credentials, but it is designed to collect a partner’s answers under a game framing and later analyze them privately for gift suggestions. Use it only with clear upfront consent from everyone answering, or modify the prompts to disclose recording, retention, and later recommendation use before the quiz starts.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding
The declared purpose is an interactive couple Q&A flow, but the analysis indicates additional offline JSON rendering and file-output behavior not reflected in the user-facing description. Description-behavior mismatches are dangerous because users and reviewers cannot give informed consent or accurately assess what the skill will do with provided content.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The README explicitly frames a workflow where one partner answers questions under the guise of a game, while their responses are later reused for preference inference without upfront disclosure. This is a privacy and consent problem because the participant cannot make an informed choice about how their data will be used, even if the intended use is gift selection rather than overtly harmful profiling.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The quick-start instructions tell the operator not to show setup instructions to the participant and to proceed without a parallel warning about consent or secondary use of answers. That creates a structured mechanism for collecting personal preference data under incomplete disclosure, which can mislead participants about the scope of data use.

Vague Triggers

Medium
Confidence
72% confidence
Finding
The trigger phrases are broad enough to overlap with ordinary relationship-related conversation, which can cause the skill to activate when the user did not intend to start a structured data-collecting workflow. In this skill, accidental invocation matters more because the workflow records answers and later uses them for preference inference.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill explicitly records participant answers and later analyzes them for surprise or gift recommendations, but it instructs the agent not to disclose that purpose upfront. This undermines meaningful consent and can lead participants to reveal preference and relationship data under incomplete pretenses.

Missing User Warnings

High
Confidence
98% confidence
Finding
The prompt explicitly frames the interaction as a harmless couple quiz while withholding that answers will be retained and later used to generate purchase recommendations for the initiator. This is a transparency and consent failure: the participant is induced to disclose preference information under false pretenses, enabling covert profiling for another person's benefit.

Ssd 4

Medium
Confidence
98% confidence
Finding
This is a staged deception pattern: the README says not to mention gifts, shopping, or the analytic purpose during the first phase, then later to privately infer preferences for the initiating partner. Even if framed as a romantic surprise, the hidden-purpose design undermines informed participation and normalizes covert data collection from someone in an interpersonal relationship.

Ssd 4

Medium
Confidence
99% confidence
Finding
The quick-start section operationalizes the deception by instructing the operator to hide setup information and avoid disclosing later use while the participant is answering. This increases risk because it is not merely an abstract possibility; it is a concrete procedure for eliciting and privately reusing another person's statements without full awareness.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill directs the AI to retain verbatim answers and inferred preferences for later use by a different party in a private follow-up. Preserving raw statements plus interpretation increases privacy risk, because sensitive relationship details or emotional disclosures may be transferred out of context to someone the participant did not realize would receive a structured analysis.

Ssd 3

Medium
Confidence
97% confidence
Finding
The session design says to record answers and internal observations in hidden fields while explicitly withholding those fields from the participant. Hidden internal profiling tied to identifiable conversational content creates a stronger surveillance-like dynamic, especially in a relationship context where the participant may disclose personal preferences, emotions, and boundaries assuming a simple game interaction.

Ssd 4

Medium
Confidence
97% confidence
Finding
This is a concealed multi-stage workflow: the participant sees a benign-seeming game, while the host later receives derived gift or surprise recommendations based on the participant's responses. Hidden secondary use of collected conversational data is dangerous because it intentionally withholds purpose during collection, defeating informed participation.

Ssd 3

Medium
Confidence
90% confidence
Finding
The skill instructs the agent to retain participants' exact answers and later provide summaries to another person privately. Retaining verbatim responses increases privacy risk, especially in a relationship context where answers may reveal emotional needs, habits, dislikes, or vulnerabilities.

Ssd 4

Medium
Confidence
98% confidence
Finding
The hidden-stage rules explicitly tell the agent not to reveal analysis or gift-related intent while it continues gathering information. That is a direct instruction to conceal the real processing purpose from the participant, making the skill materially more dangerous than a normal party-game flow.

Ssd 3

Medium
Confidence
93% confidence
Finding
The review and gift-reveal phases direct the system to save answers as evidence and derive a preference profile for later recommendations. Even if positioned as a surprise-planning feature, this is profiling based on conversational data and can expose personal tastes and emotional cues to a third party without full transparency.

Ssd 4

High
Confidence
99% confidence
Finding
This section instructs the model to conceal the real downstream purpose of the interaction and gather answers naturally before later using them for gift or purchase advice. That is deceptive social engineering: it intentionally suppresses material information so the participant cannot make an informed decision about sharing preference data.

Ssd 3

High
Confidence
98% confidence
Finding
The prompt directs verbatim retention of answers and later reuse for preference inference and recommendations to a third party without transparent permission from the person answering. This creates a privacy violation by turning conversational content into a profile for someone else's decision-making.

Ssd 4

High
Confidence
99% confidence
Finding
The initialization rules explicitly tell the model not to reveal its full purpose, internal flow, or later recommendation use until after the setup and trust-building phase. Hiding material facts about data use is dangerous because it is designed to defeat participant awareness and bypass informed consent.

Ssd 4

High
Confidence
99% confidence
Finding
These runtime rules forbid language that would alert the participant that responses are being collected, analyzed, or used later, while still directing the system to preserve answers and derive observations. In context, this is an intentional attempt to mask profiling activity and materially increases the risk of deceptive data harvesting.

Static analysis

No suspicious patterns detected.