Back to skill

Security audit

psych312-scenario-analysis

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only exam-prep skill that changes how the agent analyzes psychology scenarios, with no code execution or data access.

Install this only if you want the agent to apply a 312 psychology exam framework to scenarios. For personal distress, diagnosis, crisis support, or ordinary conversation, do not rely on this skill as clinical advice and consider disabling or avoiding it unless you explicitly want exam-style concept mapping.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description says it should trigger on essentially any life scenario, story, dialogue, or interpersonal event, which is so broad that it can activate during ordinary conversation rather than only when the user explicitly wants exam-style psychology analysis. Overbroad activation can cause unintended interception of general chats, increase privacy risk around sensitive personal narratives, and override more appropriate safety-aware handling for mental-health-adjacent content.

Vague Triggers

High
Confidence
96% confidence
Finding
The auto-trigger rule states that any user input containing stories, behavior snippets, life scenes, film plots, interpersonal events, or student cases should activate the skill, but it provides no boundary for when it must not activate. This ambiguity is dangerous because many normal or sensitive conversations fit these categories, allowing the skill to engage without clear consent and potentially produce reductive psychological labeling in contexts that need general assistance or safer mental-health routing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.