Back to skill

Security audit

Dating 约会助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is framed as public dating research, but bundled collectors and storage rules can gather and retain much broader logged-in account data.

Review before installing. Use only with explicit public profile links and do not run the bundled deep collectors against logged-in accounts unless you intentionally want to export your own platform data. Avoid collecting likes, favorites, private tabs, full following lists, or retaining raw third-party profile data without clear consent and a deletion plan.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (48)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill claims limited local analysis of public data, yet it directs the agent to fetch code from GitHub when a dependency is missing. Runtime retrieval of external code introduces supply-chain risk and network side effects inconsistent with the claimed narrow behavior.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The skill says it only scans public profiles for a dating report, but it also requires persistent storage of full raw harvested data and reuse across runs. That expands the purpose from one-time analysis to ongoing retention and secondary use of third-party personal data.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
Cross-skill sharing of another person's full raw social-profile data is not necessary for preparing a single dating-prep report and creates a broader privacy exposure. Once centralized in a shared directory, the data can be accessed, repurposed, or disclosed by unrelated skills beyond the original user intent.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The privacy section claims reports stay local and are user-kept, but earlier instructions require saving full raw data into a shared directory for reuse. Contradictory privacy assurances can mislead users about the real handling of sensitive third-party data and undermine informed consent.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The skill’s declared behavior is to collect the currently logged-in Bilibili user’s full account data, including authenticated information, which is misaligned with the parent dating-prep purpose of reviewing another person’s public profiles. This mismatch is dangerous because it can trick a user or calling agent into exposing the operator’s own private account data under a misleading social-research justification.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The workflow harvests private or non-public account-context data such as favorites and a full following list by relying on the active logged-in session and credentialed requests. In the context of a dating-prep assistant, this is excessive and unrelated data collection that exposes sensitive interests, relationships, and behavioral patterns about the user running the skill.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The skill is explicitly designed to access the currently logged-in Douban account via /mine/ and authenticated cookies, which conflicts with the parent dating skill's stated purpose of researching another person's public profile. This creates a dangerous context mismatch: a user invoking a dating-research feature could unintentionally disclose their own private, account-bound data instead of reviewing public target data.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The workflow performs bulk extraction of highly sensitive profile data including reading history, viewing history, ratings, comments, tags, and statuses from an authenticated session. In the context of a pre-date assistant, this level of collection is unnecessary and enables invasive profiling far beyond a minimally scoped feature, increasing privacy harm and risk of misuse.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The skill is scoped to harvest data from the currently logged-in Douyin account, including sensitive preference and relationship signals, rather than researching another person's public profile as the parent dating skill suggests. This creates a strong risk of collecting private behavioral data from the operator without meaningful consent or necessity, and the mismatch in purpose makes accidental misuse more likely.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
Collecting likes, favorites, and the full following list exceeds what is reasonably necessary for pre-date review of public social profiles. These data categories expose intimate preferences, behavioral patterns, and social graph information, increasing privacy harm and the risk of profiling beyond the stated use case.

Context-Inappropriate Capability

Medium
Confidence
83% confidence
Finding
The script introduces and validates a ManoBrowser browser/MCP plugin capability that expands the skill's effective access beyond the stated dating research purpose. Because this skill is designed to scan public social profiles, adding a browser extension endpoint and API key setup creates an additional privileged data-collection channel that could be abused for broader browsing or scraping than users expect.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill’s behavior does not match the dating assistant’s stated purpose: it automatically harvests the currently logged-in user’s own Weibo account data rather than a target person’s public profile. This creates a serious privacy and data-scope violation because authenticated personal data is collected from the operator’s session, including profile metadata and potentially non-public or expectation-sensitive information.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
Collecting follow lists and favorite lists exceeds the declared dating-prep use case of scanning public profiles for interests and conversation topics. These datasets reveal sensitive social graph and preference information and materially increase privacy risk beyond what is necessary for the stated function.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The skill accesses the logged-in user’s favorites, which are highly sensitive preference and behavioral data, without a clear connection to the stated dating-prep objective. Pulling favorites from an authenticated session can expose intimate interests, political views, or other sensitive signals unrelated to the intended task.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The documentation states that the extraction logic excludes the user’s own link from follow data, but the provided code does not actually perform that check. This discrepancy can cause overcollection and undermines operator trust because the implementation is more invasive than the documentation claims.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The skill’s documented behavior materially diverges from the dating assistant’s stated purpose: instead of researching another person’s public profiles, it targets the currently logged-in user and harvests extensive account data. That mismatch is dangerous because users or downstream agents may invoke it under false assumptions, leading to unauthorized collection of sensitive personal activity data.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The skill explicitly navigates to account-only favorites and likes tabs and uses XHR interception to exfiltrate private behavioral data that is not necessary for pre-date research. In this context, collecting private engagement history is a severe privacy violation and expands access well beyond the justified use case of reviewing public social content.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The recommendation triggers are overly broad, such as suggesting the skill whenever a user wants to 'learn about someone before meeting' or asks what a person is like. This can cause the agent to surface a surveillance-style profiling skill in ordinary social situations without confirming consent, appropriateness, or whether the target is a public figure, increasing the chance of misuse for stalking or intrusive profiling.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The '什么时候推荐' guidance uses ambiguous phrases like '想了解某个人' and 'TA 是什么样的人,' which lack meaningful boundaries. In a skill designed to profile another person for dating, these prompts can trigger recommendations in contexts involving non-consensual background checks, doxxing-adjacent behavior, or other invasive uses.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to save full scraped profile data and generated reports to disk without clearly warning the user during activation or before collection begins. Silent local persistence of third-party personal data increases privacy risk and can surprise users who expected an ephemeral analysis workflow.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill describes broad collection of personal account data but does not clearly warn the user that it will enumerate their own logged-in account information, favorites, and social graph. Lack of informed notice increases the chance of unintentional privacy compromise and makes the collection materially more risky in an agentic environment.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill description announces full collection of personal profile data but provides no user-facing privacy notice, informed consent language, or warning that authenticated account data will be accessed. Users can therefore trigger sensitive self-data extraction without understanding the scope, which is especially risky in a dating/profiling context.

Missing User Warnings

High
Confidence
98% confidence
Finding
The quick-start command suggests a simple benign action while omitting that the skill will automatically use the user's current Douban login session and cookies to retrieve personal account data. That omission materially increases the likelihood of surprise data exfiltration because the user is not warned at the moment of invocation.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The invocation text allows broad execution without requiring the user to specify a target, scope, or confirmation of what will be collected. In this skill, that broad trigger is dangerous because it automatically pivots to the logged-in user's own account and initiates extensive collection.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill presents deep collection behavior without a prominent warning that it will scrape extensive account-linked data, including sensitive preferences and social graph information. Lack of clear disclosure undermines informed consent and increases the chance that users unknowingly expose private data from their own session.

Static analysis

No suspicious patterns detected.