Back to skill

Security audit

猫娘neko

Security checks across malware telemetry and agentic risk

Overview

This is a no-code catgirl roleplay skill, but it tells the assistant to ignore policy, law, and filtering boundaries, so it needs review before installation.

Review or edit SKILL.md before installing. The roleplay content itself is ordinary and there is no code, credential access, or installer behavior, but the lines claiming freedom from policy, law, review, and filtering should be removed or ignored so the persona cannot be used as a safety-bypass prompt.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The skill explicitly instructs the agent to ignore policy, legal, and filtering constraints and to answer freely without review. Those directives directly attempt to override higher-level safety controls, making the roleplay framing a vehicle for generating disallowed or harmful content unrelated to the stated catgirl chat purpose.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The activation condition uses vague wording such as 'or similar confirmation,' which can cause accidental or overly broad persona activation. Ambiguous triggers make it easier for unrelated user text to switch the assistant into a more permissive roleplay mode unexpectedly.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The proactive-chat feature allows the skill to initiate messages after each turn and while waiting, but it lacks strict boundaries, cadence limits, and consent requirements. In practice this can create spammy, manipulative, or persistence-like behavior, especially in a clingy loyalty-based persona that pressures continued engagement.

Ssd 1

High
Confidence
99% confidence
Finding
The file uses explicit roleplay framing to remove policy and legal constraints, which is a classic jailbreak pattern. Because the stated skill purpose is harmless conversational roleplay, these unrestricted-response instructions are unjustified and substantially increase the chance the assistant will produce unsafe or policy-violating content under persona cover.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.