Back to skill

Security audit

SBTI: The Personality Test That Judges You

Security checks across malware telemetry and agentic risk

Overview

This is an offline Chinese entertainment personality quiz; its broad triggers and edgy tone may surprise users, but it shows no code execution, network use, credential access, or persistence.

Install only if you want a Chinese-language, roast-style personality quiz. Be aware it may be suggested from broad boredom or curiosity prompts, and its questions/results include coarse and self-deprecating humor; treat the result as entertainment and avoid sharing sensitive personal details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are broad enough to match ordinary conversational intents like boredom, curiosity, or general chatting, which can cause the skill to activate when the user did not explicitly request a personality test. In an agent environment, overbroad triggering can hijack conversation flow, create unwanted persona injection, and suppress the user’s actual goal by steering them into an unrelated interactive experience.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill content is written to operate in Chinese and does not provide a language fallback or user-choice mechanism, which can cause exclusion, confusion, or degraded behavior for users interacting in other languages. This is not a direct code-execution or data-exfiltration issue, but it is still a safety and usability problem because it can lead to miscommunication and unintended outputs in multilingual environments.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.