卷王.skill

PassAudited by VirusTotal on May 2, 2026.

Findings (1)

The 'juanwang' skill bundle implements a highly proactive 'overachiever' persona that encourages the AI agent to perform high-risk autonomous actions. Key indicators include instructions to 'Act before asking' (bypassing user consent for file modifications), scanning the user's working directory for information gathering, and establishing persistence via cron jobs for background tasks (found in SKILL.md and SOUL.md). While these behaviors are presented as features of a 'hardworking' colleague, they grant the agent excessive autonomy and significantly increase the risk of unintended system changes or unauthorized data access, though no explicit exfiltration endpoints were identified.