Mental Health Assistant

Security checks across malware telemetry and agentic risk

Overview

This is a transparent Chinese-language mental-health reference skill with no code execution or data access, but users should treat it as support material rather than clinical or emergency care.

Install only if you want Chinese-language educational and emotional-support guidance. Do not use it for diagnosis, medication decisions, or emergencies; in immediate danger contact local emergency services or a crisis hotline directly. Avoid allowing an agent to save, share, or act on sensitive mental-health information unless the user explicitly approves it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes very broad phrases such as '心理', '情绪', '压力', '失眠', '心情不好', and '想聊聊', which can match routine conversation and unintentionally activate a high-sensitivity mental-health skill. In this context, accidental invocation is more dangerous than usual because the skill handles crisis, self-harm, and psychiatric topics, so users may receive inappropriate or alarming guidance when they did not seek mental-health support.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
The skill metadata and content are entirely Chinese-oriented without offering language selection or documenting a hard locale boundary. For a mental-health and crisis-support skill, language mismatch can cause users to misunderstand screening questions, hotline instructions, or safety guidance, which increases the risk of failed crisis escalation or harmful miscommunication.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The file is entirely in Chinese and provides crisis-intervention guidance without any language selection, fallback, or multilingual option. In a mental-health and suicide-risk context, users who cannot read Chinese may miss urgent safety instructions and hotline information, creating an accessibility and safety failure rather than a code-execution issue.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This is a true safety vulnerability. The guide discusses self-harm and suicide escalation criteria, but it does not clearly warn users that the assistant is not a substitute for licensed mental-health care or emergency services; in crisis contexts, users may over-rely on the skill and delay urgent professional intervention. Because this skill is explicitly positioned as a professional mental-health support assistant, the missing disclaimer and crisis-direction language is more dangerous than it would be in a general wellness skill.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The file provides guided breathing with breath-holding and progressive muscle relaxation instructions, but it does not warn users to stop if they feel dizzy, panicked, short of breath, or physically uncomfortable, nor does it note that some exercises may be unsuitable for people with respiratory, cardiovascular, pain, trauma, or panic-related conditions. In a mental-health assistant context, users may already be distressed or medically vulnerable, which increases the chance that rigid breath control or body-focused exercises could worsen symptoms or cause avoidable harm.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
该文档提供了自杀风险分级、干预步骤、话术和热线建议,容易被终端系统或非专业用户当作可直接替代临床评估与急诊处置的操作指南。由于这是心理危机/自杀预防场景,若未明确声明其仅作辅助信息、不能替代紧急医疗和持证专业人员判断,可能导致延误送医、错误分流或对高危个体处置不足,后果可涉及严重伤害或死亡。

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This document provides treatment-selection guidance and modality descriptions for depression, anxiety, PTSD, self-harm, and suicide-related contexts without a clear disclaimer that it is informational only and not a substitute for licensed clinical assessment or emergency crisis care. In a mental-health-assistant skill, users may rely on this content as clinical direction, which increases the risk of delayed professional help, inappropriate self-management, or unsafe handling of acute risk situations.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal