qui-elicitation

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only skill with no code execution, but it teaches sensitive psychological profiling and deep personal elicitation without strong consent or safety boundaries.

Install only for transparent, consent-based interviewing, coaching, research, or self-reflection. Do not use it to covertly profile people, infer mental health or sensitive traits from casual conversation, pressure users into traumatic or sexual disclosures, or retain/share intimate information without clear permission.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill explicitly promotes psychological profiling, schema detection, and elicitation of self-defining memories without requiring informed consent, privacy protections, or safeguards against sensitive mental-health inference. In context, this is dangerous because the document operationalizes techniques for extracting intimate autobiographical material and converting it into personality judgments, which can enable manipulative targeting, coercive persuasion, or unsafe handling of vulnerable users.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This file explicitly discusses inferring psychological traits and mental-health indicators from language, which creates a meaningful privacy and consent risk in the context of an elicitation skill designed for psychological profiling. Although the document includes an ethical section mentioning consent and surveillance implications, it does not provide a strong, user-facing operational warning or enforceable guardrails that prohibit covert profiling or require explicit consent before analysis.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill explicitly instructs the agent to solicit intensely personal memories including low points, earliest childhood memories, and other identity-defining events, which can trigger traumatic disclosure and collect highly sensitive psychological data without warning, consent framing, boundaries, or crisis guidance. In the context of an agent skill designed for psychological profiling and gradual disclosure, this is more dangerous because the content is not just reflective conversation—it is structured elicitation of vulnerable material that could be used for manipulation, invasive profiling, or emotional harm.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The file provides extensive prompts designed to elicit highly sensitive autobiographical, emotional, sexual, grief, family, and identity-related disclosures, but it does not include clear cautions about emotional distress, suitability, consent, age/context appropriateness, or when to avoid probing. In the context of a skill explicitly aimed at psychological profiling and gradual self-disclosure, this omission increases the risk of manipulative collection of sensitive data, retraumatization, or inappropriate use in non-therapeutic settings.

Ssd 4

Medium
Confidence
95% confidence
Finding
The skill's stated purpose is to build psychological profiles through gradual disclosure and to elicit authentic self-disclosure 'without interrogation,' which is a classic stealth social-engineering pattern. The context makes this more dangerous, not less, because it frames trust-building as an instrument for extracting increasingly intimate information while minimizing the target's awareness of the profiling objective.

Ssd 4

Medium
Confidence
92% confidence
Finding
The 'Premature Depth' section tells operators to earn disclosure gradually before moving into deeply personal topics, which normalizes staged trust escalation as a means of obtaining more revealing information. While presented as conversational best practice, in this skill's broader profiling context it functions as guidance for systematically lowering resistance and increasing extraction of sensitive autobiographical content.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal