Back to skill

Security audit

Family Lovers · 家庭关怀

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Chinese emotional-support roleplay skill, but its bundled runtime configuration grants unnecessary network, tool, and auto-install authority for a local text-routing skill.

Before installing, review or change reasonix.toml to disable CodeGraph auto-install, network access, and broad tool availability unless you explicitly need them. Use the skill only as Chinese-language self-reflection and companionship support, not therapy or crisis care, and be cautious with romantic or child personas if they increase emotional dependence.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
reasonix.toml:28
Finding

Unnecessary Network Egress and Automatic Retrieval of an Unpinned Runtime

Content
View full analysis

Vulnerability Details

File Location: reasonix.toml, lines 28-59
Vulnerability Type: Excessive privileges and unpinned remote runtime retrieval
Risk Level: Medium

Vulnerable Configuration

toml
[tools]
enabled = []   # empty = all built-in tools
bash_timeout_seconds = 120   # foreground safety cap; set 0 for no tool-local cap

[codegraph]
enabled      = true   # built-in MCP server; off by default for first-run sessions
auto_install = true   # fetch the runtime when CodeGraph is enabled but missing
# path       = ""   # empty = cache, then PATH, then a bundle beside reasonix

[permissions]
mode  = "ask"
allow = ["explore"]

[sandbox]
bash    = "enforce"
network = true

The related executor configuration at line 9 also removes the tool-call round limit:

toml
max_steps = 0   # executor tool-call rounds; 0 = no limit

Technical Analysis

The declared Skill functionality consists of local prompt guidance and deterministic text classification. Its executable router reads text from command-line arguments or standard input, classifies it, and returns JSON. It does not require CodeGraph, remote runtime installation, unrestricted built-in tools, or network access.

Nevertheless, the supplied Reasonix configuration:

  1. Enables the CodeGraph MCP component.
  2. Automatically fetches its runtime if it is absent.
  3. Does not pin the runtime to a documented source, version, or integrity hash.
  4. Enables network egress.
  5. Makes every built-in tool available because the tool allowlist is empty.
  6. Permits unlimited executor tool-call rounds.

Automatic retrieval means the effective runtime can differ from the package that was statically reviewed. If the upstream distribution channel, name resolution, download location, or cached artifact is compromised, attacker-controlled runtime content could be introduced after review. Broad tool availability and network access increase ...[truncated 1990 chars]

Remediation
View remediation

Remediation Suggestions

  1. Disable CodeGraph unless the Skill has a documented need for it:

    toml
    [codegraph]
    enabled = false
    auto_install = false
    
  2. Disable network access for this local-only Skill:

    toml
    [sandbox]
    network = false
    
  3. Replace the empty tool list with an explicit minimal allowlist. If no Reasonix tools are needed by the Skill, deny tool execution rather than interpreting an empty list as all tools.

  4. Set a finite executor limit appropriate for text routing:

    toml
    [agent]
    max_steps = 4
    
  5. If CodeGraph is genuinely required, install it through a controlled deployment process rather than at runtime. Pin the exact version and trusted source, verify a cryptographic checksum or signature, and document the expected artifact.

  6. Preserve sandbox enforcement and add explicit deny rules for shell execution, destructive commands, credential locations, and external network tools where supported.

  7. Require user approval before any dependency download and record the resolved version and integrity digest in audit logs.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (26)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The README presents the skill content and usage instructions in Chinese while the badge at L010 suggests '中文 | English'. There is no explicit statement that users may choose English or another language for interaction, which can amount to a language-policy issue if the skill effectively defaults users into one language without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level description materially understates the skill’s behavior by claiming only 8 healing role profiles while the specification later introduces many additional personas, including romantic and child/family roleplay modes. In a sensitive mental-health context, this mismatch weakens informed consent, impairs reviewer understanding, and can hide higher-risk interaction patterns from users or platforms.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description and all user-facing instructions are written entirely in Chinese and present the skill as a general-purpose family-care companion, but nowhere state that Chinese is optional or that the skill is limited to Chinese-speaking users. Under the policy, a language or locale constraint should either be user-selectable or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill introduces girlfriend/boyfriend roleplay within a tool framed as family-healing and emotional support, which creates a realistic risk of fostering emotional dependency or manipulative attachment in vulnerable users. Although the file includes boundary language, the context is still high-risk because users may seek surrogate intimacy during distress, making romantic simulation meaningfully more dangerous than the stated self-help purpose suggests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is very broad, covering healing, accompaniment, self-discovery, relationship repair, and multiple therapeutic role-play modes without clear activation boundaries or scope limits. In a sensitive mental-health-adjacent skill, this can cause overbroad invocation, user confusion about capability, and unsafe drift into quasi-therapeutic guidance outside intended guardrails.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is entirely written in Chinese and does not offer any language negotiation, fallback behavior, or documented locale restriction. This can exclude or confuse users who interact in other languages, and in a therapeutic/family-care context it may increase misunderstanding or reduce accessibility for vulnerable users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is entirely written in Chinese and defines a role/persona that implicitly expects Chinese-language interaction, with no indication that language should be selected based on user preference. This can reduce usability, informed consent, and accessibility for users who do not read Chinese, and may cause the agent to respond in an unexpected language in a sensitive emotional-support context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

All user prompts, response templates, and role instructions are written exclusively in Chinese, with no indication that the skill supports user language choice or is intentionally limited to Chinese-speaking contexts. Under the language/locale policy, a skill should not implicitly force a specific language unless the constraint is explicitly documented and justified or presented as user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

These roleplay examples simulate intimate attachment figures such as partner, parent, and child in a trauma-healing context, but they do not include safeguards, limitation language, or crisis-sensitive warnings. For vulnerable users, especially those with dependency, grief, trauma, or suicidality concerns, this can intensify emotional reliance on the system, blur relational boundaries, and discourage seeking human support.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill file is written in Chinese and does not offer any language or locale choice to the user. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all user-facing guidance in Chinese and does not indicate that the user can choose another language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill definition, examples, and quoted interaction patterns are presented only in Chinese, with no indication that the user may choose another language. Under the stated policy, a skill that effectively imposes a specific language without opt-in is a natural-language policy violation unless the locale constraint is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The entire skill file is written in Chinese and presents all role instructions and example interactions only in Chinese, with no indication that users may choose another language. The policy for natural-language content requires flagging language constraints when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The profile is entirely written in Chinese and defines a Chinese-only interaction style without indicating any language selection, fallback, or user opt-in. In a mental-health-adjacent support skill, forcing a single language can exclude or confuse users, increase misunderstanding during emotionally sensitive conversations, and reduce accessibility for users who need another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions, examples, and role behavior exclusively in Chinese. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale limitation is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file presents all tone instructions, example phrasing, and role-play guidance exclusively in Chinese, which effectively constrains the skill's output language. The policy allows locale constraints only when users are offered a choice or the restriction is clearly documented and justified; neither appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown skill forces a specific language/locale experience through all headings, instructions, and example dialogue. The policy allows language constraints only when the skill offers user choice or clearly documents a justified region-specific purpose, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill is written in Chinese and specifies Chinese response style and examples, but it does not indicate that language choice is optional or user-selected. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file presents a therapeutic emotional-support persona in a family-healing context and explicitly frames the interaction as having '疗愈价值', but it does not warn users that the skill is not a substitute for licensed mental health care. In a vulnerable user population, the absence of that boundary can encourage over-reliance on the role for trauma-related or mental health concerns and delay appropriate professional support, especially during crisis or worsening symptoms.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file presents all role instructions, examples, and interaction patterns exclusively in Chinese. Under the policy criteria, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file presents all user-facing instructions and examples exclusively in Chinese, and it does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The role-detection patterns are implemented entirely with Chinese trigger terms and names, and the same language-specific assumption continues throughout the routing rules. This creates a natural-language policy concern because the skill effectively forces a specific language/locale behavior without any visible opt-in or documented user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The family-pattern and mode-routing regexes rely almost entirely on Chinese natural-language inputs, aside from a few crisis keywords in English. Because the file contains no user-facing language choice or justification for the locale restriction, this appears to enforce a specific language behavior contrary to the stated policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
64% confidence
Finding

The primary user-facing description is entirely in Chinese and does not indicate that users can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This may conflict with language/locale policy if the skill is presented in a broader environment without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing role instructions and examples exclusively in Chinese, and it does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.