Back to skill

Security audit

qingtian-psychology-self-study

Security checks for vulnerabilities and agentic risk

Overview

This local psychology training skill is coherent, but its built-in assessments can miss crisis answers and can overstate clinical care advice, so it needs careful review before use.

Use this only as a local training and education aid, not as clinical triage or crisis support. Before using its assessment reports with real people, fix the crisis metadata for all self-harm/violence/severe-risk items and make report advice scale-specific, especially for FFMQ and other nonclinical trait measures.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (290)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
Import/export and restore functionality that overwrites progress.json introduces integrity risk, especially when paired with broad filesystem and shell capabilities. If the import source or destination paths are not tightly constrained, an attacker could cause destructive overwrites, state poisoning, or recovery confusion in the local workspace.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
Import/export and restore functionality that overwrites progress.json introduces integrity risk, especially when paired with broad filesystem and shell capabilities. If the import source or destination paths are not tightly constrained, an attacker could cause destructive overwrites, state poisoning, or recovery confusion in the local workspace.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
Import/export and restore functionality that overwrites progress.json introduces integrity risk, especially when paired with broad filesystem and shell capabilities. If the import source or destination paths are not tightly constrained, an attacker could cause destructive overwrites, state poisoning, or recovery confusion in the local workspace.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
Import/export and restore functionality that overwrites progress.json introduces integrity risk, especially when paired with broad filesystem and shell capabilities. If the import source or destination paths are not tightly constrained, an attacker could cause destructive overwrites, state poisoning, or recovery confusion in the local workspace.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
Import/export and restore functionality that overwrites progress.json introduces integrity risk, especially when paired with broad filesystem and shell capabilities. If the import source or destination paths are not tightly constrained, an attacker could cause destructive overwrites, state poisoning, or recovery confusion in the local workspace.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
Import/export and restore functionality that overwrites progress.json introduces integrity risk, especially when paired with broad filesystem and shell capabilities. If the import source or destination paths are not tightly constrained, an attacker could cause destructive overwrites, state poisoning, or recovery confusion in the local workspace.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
Import/export and restore functionality that overwrites progress.json introduces integrity risk, especially when paired with broad filesystem and shell capabilities. If the import source or destination paths are not tightly constrained, an attacker could cause destructive overwrites, state poisoning, or recovery confusion in the local workspace.

Natural-Language Policy Violations

High
Confidence
98% confidence
Finding
A potentially crisis-indicating item is explicitly marked non-crisis and there is no fallback crisis rule in the safety section. In a depression screening context, this can suppress escalation for users expressing severe impairment or hopelessness-adjacent content, increasing the chance of missed intervention during a sensitive workflow.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The scale includes explicit self-harm and violence-related items such as suicidal ideation and urges to harm others, but the item-level and global safety metadata leave crisis detection disabled. In a mental-health skill, this can cause the system to collect high-risk disclosures without triggering escalation, warning, or emergency resource presentation, increasing the chance of unsafe handling of an acute crisis.

Missing User Warnings

High
Confidence
99% confidence
Finding
High-risk items are present but are not accompanied by any crisis warning or escalation metadata, despite the file containing questions about ending one's life and harming others. This creates a direct safety gap: the application may treat severe disclosures as ordinary scale responses and continue normal scoring or coaching rather than initiating emergency-oriented safeguards.

Missing User Warnings

High
Confidence
99% confidence
Finding
The safety block is effectively empty even though the scale contains severe psychiatric content, including suicidality, violent impulses, hallucination-like experiences, and persecutory beliefs. In a psychology training/self-study environment, an empty global safety configuration materially increases the risk that dangerous responses will not be recognized or handled with appropriate urgency.

Missing User Warnings

High
Confidence
99% confidence
Finding
A user-facing assessment item about being better off dead appears without any embedded warning, escalation metadata, or response handling instructions. Because this file is part of a psychology-related skill, omission of crisis UX and escalation controls could lead the system to continue a normal questionnaire flow after a user discloses possible self-harm thinking, delaying urgent support.

Missing User Warnings

High
Confidence
95% confidence
Finding
This markdown file instructs the AI to act as a counselor persona for sensitive emotional situations, including self-harm or harm-to-others scenarios, but it does not include any explicit user-facing warning about the limits of AI support. For mental-health-adjacent skills, omission of such a warning can affect user safety by encouraging reliance on the skill in situations that may require licensed or emergency assistance.

Missing User Warnings

High
Confidence
95% confidence
Finding
This markdown file states it is for childhood trauma, emotional dysregulation, complex trauma, and includes self-harm as an example topic, but it does not warn users about safety limitations, crisis situations, or the need to seek qualified human help when at risk. For a mental-health-oriented skill that may influence vulnerable users, the omission is a meaningful safety disclosure gap.

Missing User Warnings

High
Confidence
90% confidence
Finding
The file includes concrete instructions for approaching '流放者' / deep trauma material and '取回' painful memories, which can intensify distress or destabilize vulnerable users if used without immediate grounding, screening, and crisis safeguards. In a psychology training skill, these directions may be reproduced in simulated or real-seeming interactions, increasing the chance that users are guided into emotionally unsafe territory without adequate warning.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The FFMQ is a mindfulness trait questionnaire, not a symptom severity or diagnostic screening tool, yet the report converts ordinary factor scores into clinical-style advice such as observing for worsening, seeking professional assessment, and 'when to seek care' thresholds tied directly to nonclinical subscale values. In a mental-health context, this can mislead users into overinterpreting benign trait scores as signs of disorder, causing inappropriate reassurance, unnecessary escalation, or distorted self-assessment.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
This report applies a mindfulness trait questionnaire (FFMQ) as if it were a symptom severity screener, then produces advice such as 'light to moderate,' observation windows, and referral triggers. In a psychology-training skill, that mismatch is especially dangerous because users may treat the output as clinically meaningful triage despite the instrument not supporting those conclusions, leading to false reassurance or unnecessary escalation.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The report is for the FFMQ mindfulness questionnaire, which measures mindfulness-related traits rather than psychiatric symptom severity, yet it gives clinical escalation advice such as observing for two weeks, seeking professional psychological evaluation, and using score thresholds as reasons to seek psychiatric care. In a mental-health skill, this mismatch can mislead users into unnecessary medical concern or inappropriate help-seeking, and it undermines safe boundaries by presenting non-diagnostic trait scores as quasi-clinical risk indicators.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The inline guidance explicitly treats ordinary mid-range FFMQ scores (for example, scores of 3 classified as '中等') as thresholds for seeking psychiatric or psychological care. That is clinically incoherent for this instrument and can cause false alarm, distress, or unnecessary escalation in a sensitive mental-health context where users may over-trust automated reports.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
This FFMQ report incorrectly presents care-escalation and psychiatric referral guidance based on mindfulness trait subscale thresholds, which the instrument is not designed to support. In a psychology self-study skill, users may treat the report as clinically meaningful triage advice, leading to inappropriate reassurance, unnecessary alarm, or delayed care if real symptoms are misinterpreted through an invalid framework.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
This FFMQ report introduces symptom-severity framing ('轻到中度区间') and treatment/escalation guidance that the mindfulness questionnaire does not validly support. In a psychology self-study skill, users may over-trust the report as quasi-clinical triage, leading to inappropriate reassurance or unnecessary/incorrect help-seeking based on invalid interpretation.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The report claims decision-making authority about when to seek psychiatric/psychological care based on FFMQ factor thresholds such as '达到 3 即进入中等级', but those thresholds do not justify medical disposition. That creates unsafe pseudo-clinical triage in a mental-health context, where users may treat unsupported cutoffs as professional advice.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
This FFMQ mindfulness report presents clinical-seeming risk stratification and care-seeking advice that do not match what the instrument measures. In a psychology self-study skill, users may incorrectly infer that ordinary mindfulness trait scores indicate a mental health condition or need for treatment, causing unnecessary alarm, inappropriate help-seeking, or distorted self-assessment.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The 'when to seek care' section says that reaching a score of 3 ('medium') on FFMQ dimensions like awareness/action, non-judging, or non-reactivity is itself a reason to seek psychiatric or psychological help. That directly conflicts with the page's own semantics and can mislead users into treating normal or middling mindfulness scores as pathology, which is especially risky in a mental-health-adjacent tool.

Env Variable Harvesting

High
Category
Data Exfiltration
Content
os.path.join("tests", "dryrun", "r8_multidim.py"),
]

ENV = dict(os.environ)
ENV.setdefault("PYTHONIOENCODING", "utf-8")
Confidence
60% confidence
Finding
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Static analysis

No suspicious patterns detected.