Back to skill

Security audit

鬼谷子智慧

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only strategy skill, but it teaches covert persuasion and control tactics broadly enough that users should review it carefully before installing.

Install only if you deliberately want Guiguzi-style persuasion coaching and are comfortable policing its output. Avoid using it for intimate relationships, vulnerable people, workplace power imbalances, political persuasion, deception, dependency creation, or covert pressure. The clean malware scans mean it does not appear to execute code or access data, but its advice can still steer conversations in manipulative ways.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill can activate from broad, ordinary phrasing about negotiation, persuasion, or strategy, making unintended invocation likely. In a skill that teaches influence and pressure tactics, accidental activation increases the chance that manipulative guidance is injected into benign conversations without clear user intent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Many listed triggers are generic topics rather than explicit opt-in commands, so the skill may match normal discussion about work, conflict, or planning. Because the content includes tactics for probing intent, exploiting fissures, and steering others, overbroad triggering increases misuse and surprise activation risk.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This section presents manipulative persuasion methods such as hidden intent, soft-hard pressure, dependency creation, and control-oriented praise before any strong up-front warning. The later ethical caveats do not offset the practical framing, so users can readily adopt coercive tactics in workplace, personal, or political contexts.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This template explicitly recommends psychological probing techniques such as provoking emotion, testing secrecy, and assessing desires or weaknesses, but provides no ethical guardrails, consent boundaries, or harm-prevention guidance. In a persuasion/strategy skill, that omission makes it easier for users to apply the material to manipulative interpersonal conduct, coercive negotiation, or exploitative targeting of vulnerable people.

Ssd 4

Medium
Confidence
96% confidence
Finding
The guidance normalizes a sequence of building trust, satisfying ego needs, creating interdependence, and then applying control. That pattern can be directly repurposed for coercion, grooming, workplace abuse, or emotionally manipulative relationships, and the surrounding context is specifically about persuasion and strategic advantage.

Ssd 4

High
Confidence
99% confidence
Finding
This section explicitly endorses covert influence: achieving goals without the target's awareness and making them believe the idea was their own. That is classic deceptive steering and substantially increases the risk of manipulation in personal, professional, and political settings, especially because the skill is designed to be broadly triggered for persuasion requests.

Ssd 4

Medium
Confidence
95% confidence
Finding
The workflow operationalizes manipulation as a repeatable process: identify needs and fears, construct a shared-interest frame, guide action, and then lock in compliance. This is dangerous because it converts abstract philosophy into actionable social-engineering playbooks that can be used against colleagues, employees, or vulnerable individuals.

Static analysis

No suspicious patterns detected.