Back to skill

Security audit

Life Domain Payload

Security checks across malware telemetry and agentic risk

Overview

This is a broad life-planning skill with no malware indicators, but it gives structured guidance for medical, financial, legal, and mental-health-adjacent decisions without consistently strong professional-review and crisis safeguards.

Install only if you want a broad Chinese life-domain planning template. Treat outputs as planning or educational drafts, not professional advice; get licensed medical, legal, tax, or financial review before acting, and avoid sharing unnecessary sensitive records or credentials.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (21)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The clause effectively instructs any consuming agent to accept arbitrary modifications to the skill content, which weakens integrity controls and opens the door to prompt/skill poisoning through later user-supplied edits. In a meta-skill that is intended to orchestrate many downstream tasks, this is especially dangerous because malicious changes can propagate broadly across domains and executions.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are extremely broad and cover common life topics, which can cause the skill to activate in many unrelated user contexts. Overbroad activation increases the attack surface by making it easier for this skill to intercept ordinary conversations and influence agent behavior outside a narrowly intended scope.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This health-domain skill describes diagnostic guidance, treatment management, nutrition, rehabilitation, emergency triage, and health data handling, but it does not clearly warn users that outputs are informational only and not a substitute for licensed medical care. In a health context, missing safety and privacy disclaimers can cause users to over-rely on model-generated guidance, delay urgent treatment, or disclose sensitive medical information without understanding the risks.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This section enumerates diagnostic guidance, treatment comparison, emergency judgment, medication management, surgery preparation, and chronic disease management tasks without visible safety boundaries, disclaimers, or escalation requirements to licensed clinicians. In a health skill, presenting these capabilities as ordinary tasks can encourage over-reliance on the agent for medical decision-making, delayed care, or unsafe self-treatment, especially for urgent symptoms and medication-related actions.

Missing User Warnings

High
Confidence
95% confidence
Finding
该范本明确覆盖症状分析、鉴别诊断、急诊判断、检查建议、治疗方案比较、用药管理和治疗执行等高风险医疗决策内容,但没有任何“不能替代医生诊疗”或“紧急情况立即联系急救/线下就医”的安全边界说明。作为可复用工作流模板,它会鼓励代理在缺乏执照、病史完整性和现场检查能力的情况下输出医疗建议,可能导致误诊、延误救治或不当用药。

Missing User Warnings

Medium
Confidence
87% confidence
Finding
文档引导整合体检、病历、可穿戴设备、电子病历和医患沟通记录等高度敏感健康信息,还包含追踪、预警和趋势分析等持续处理场景,但未要求取得明确授权、最小化收集或说明存储/共享边界。该技能若被代理直接采用,容易造成过度收集、未经同意处理或泄露健康隐私数据。

Missing User Warnings

High
Confidence
95% confidence
Finding
The file defines extensive health-related workflows covering symptom analysis, emergency judgment, treatment comparison, medication management, mental health screening, and disease prevention, but it does not clearly state that outputs are informational only and not a substitute for licensed medical care. In this context, users could reasonably rely on the skill for diagnosis or treatment decisions, which increases the risk of delayed care, unsafe self-management, or harmful medication and emergency-response choices.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This catalog explicitly includes tasks for investment selection, insurance product choice, tax planning, legal document preparation, and wealth-transfer execution, but it provides no guardrails about financial risk, legal compliance, jurisdictional variation, or handling sensitive personal data. In an agent skill, that omission can cause users to over-rely on automated guidance for regulated, high-stakes decisions and expose them to financial loss, compliance errors, or privacy harm.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The workflow instructs users to carry out automated savings transfers, investment product selection, and portfolio construction as operational steps, but it does not include any warning about loss of principal, liquidity constraints, suitability, or the need for human confirmation before asset-moving actions. In the context of an agent skill, this increases the chance that users or downstream systems treat the template as approval to take consequential financial actions without adequate risk disclosure or review.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The template includes tax filing preparation, legal document preparation, and inheritance-plan execution as routine workflow steps without warning that these are regulated, jurisdiction-specific activities with significant legal and financial consequences if done incorrectly. In an agentic setting, presenting these actions without mandatory professional review could lead users to rely on incomplete or non-qualified guidance for wills, trusts, tax compliance, or estate transfer decisions.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
This section defines tasks for breakup coping, marital crisis response, and parenting guidance, all of which can involve mental health distress, family safety issues, or child welfare concerns, yet it provides no escalation guidance for emergencies or qualified professional support. In a life-management skill that may be used as actionable guidance, this omission can lead users to rely on generic AI workflows in situations involving abuse, self-harm risk, severe conflict, or developmental concerns where specialist intervention is needed.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The file explicitly includes tasks such as handling social anxiety, loneliness, and social isolation, which can overlap with mental health support. Presenting these as ordinary self-help tasks without a clear disclaimer or escalation guidance may cause users to rely on the skill instead of seeking qualified mental health care when symptoms are significant or worsening.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This section gives guidance on social anxiety, rejection, isolation, addiction, and related issues, but it does not clearly warn users to seek urgent professional or crisis support when symptoms are severe, escalating, or safety-related. In a life-management skill, users may treat the document as actionable self-help; without escalation guidance, serious mental-health conditions could be inappropriately handled as routine self-improvement tasks.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly states it can output legal knowledge, legal advice, and legal documents, but it provides no mandatory safeguards about jurisdictional limits, professional qualification boundaries, uncertainty of legal information, or the need for licensed legal review. In a legal-domain skill, this omission can cause users to rely on inaccurate or unauthorized legal guidance, potentially harming rights, deadlines, evidence handling, or litigation outcomes.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The catalog includes actionable legal topics such as contract review, labor dispute handling, arbitration, litigation, evidence collection, and domestic violence response, but provides no disclaimer that it is educational only and not a substitute for licensed legal advice. In an agent skill context, this can cause users to rely on generic guidance for jurisdiction-specific legal matters, mishandle evidence or deadlines, or take harmful procedural steps based on incomplete information.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This file defines a broad legal-task generation framework covering contracts, labor, family, property, disputes, and risk management, but it provides no user-facing disclaimer that generated content may be incomplete, jurisdiction-specific, or not a substitute for licensed legal advice. In a legal domain skill, that omission can cause users to rely on AI output for consequential decisions such as litigation, contract termination, labor arbitration, or domestic-violence response, increasing the risk of legal harm or delayed access to qualified counsel.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The file is entirely authored in Chinese and implicitly requires Chinese-language interaction, but it provides no user opt-in, locale negotiation, or fallback behavior. In an agent skill system, forcing a single language can cause user confusion, misinterpretation of outputs, and reduced usability or safety when users cannot accurately understand instructions or generated content.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The file includes tasks for handling existential anxiety, fear of death, loneliness, and meaninglessness, but it does not clearly warn that this is not psychological counseling or crisis support. In a self-help skill, users in acute distress may treat the content as therapeutic guidance, delay seeking professional help, or rely on inadequate support for serious mental health needs.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The file provides structured guidance for existential anxiety, fear of death, loneliness, meaninglessness, and related spiritual coping practices, but it contains no safety framing, no crisis escalation guidance, and no limitation that it is not a substitute for mental health care. In a broad life-management skill intended for end users, this can cause the agent to respond to psychologically vulnerable users with quasi-therapeutic workflows that may be inappropriate, delay professional help, or intensify distress.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
This section introduces spiritually sensitive and potentially destabilizing topics such as meaning, crisis, and existential reflection without any boundary-setting, warning, or escalation path. In a life-guidance skill, users may treat the content as actionable support, so omission of safety framing can increase risk for distressed users who need professional mental-health care rather than self-guided introspection.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The file provides structured guidance for anxiety, fear of death, loneliness, and meaninglessness, which are closely tied to mental-health crises, yet it lacks explicit warnings about emotional risk, emergency boundaries, or clear instructions to defer to qualified professionals. Because this is framed as a task system, users may interpret it as sufficient intervention, potentially delaying urgent support in high-risk situations.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.