Back to skill

Security audit

真实的人类

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant for personalization, but it directs agents to automatically build persistent user profiles that may include sensitive personal and psychological information without a clear opt-in step.

Review this skill carefully before installing. It has no executable malware indicators, but it is designed to persistently model users across conversations. Only use it where users have clearly opted in, can inspect and delete all profile copies, and understand that sensitive inferences may be stored unless the skill is tightened.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

other

Warning
Location
SKILL.md:61
Finding

Automatic Persistent User Profiling Without Prior Opt-In Consent

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/extraction-methods.md:47
Finding

Speculative Personal and Psychological Inferences Can Be Persisted as High-Confidence Non-Sensitive Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:93
Finding

Sensitive Profile Storage Is Described as Encrypted Without Any Encryption Implementation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill describes automatically creating and updating per-user profile files from conversations but does not clearly warn users that persistent profiling will occur. This is dangerous because users may share sensitive personal, relational, or behavioral information without informed consent, and the storage persists across sessions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough to match common conversational topics like personality analysis or understanding a person, which can cause the skill to activate unexpectedly. In this skill's context, unintended invocation is more dangerous because activation leads to profiling and persistence of personal data, increasing privacy risk without explicit user intent.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions explicitly direct the system to persistently collect, extract, and store user information after each interaction. Even though the document mentions privacy and authorization in principle, the operational workflow normalizes continuous profiling, which can capture sensitive data and create long-lived dossiers vulnerable to misuse or unauthorized access.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages broad logging of identity, cognition, emotions, behaviors, social relationships, and ongoing goals into profile and memory files. This breadth makes the skill more dangerous than ordinary personalization because it systematizes detailed person-modeling across multiple sensitive domains, enabling invasive profiling and increasing harm if exposed, inferred incorrectly, or reused beyond the user's expectations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file says health, financial, family-conflict, and psychological information require authorization and should not be proactively recorded, but the later automatic-extraction example labels clear mental-health distress and life-status data as non-sensitive. That contradiction can cause the skill to silently classify and retain sensitive personal inferences without consent, especially in a skill explicitly designed for human modeling and profiling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This guidance endorses automatic extraction of emotion, life situation, and latent needs from free-text user input without a prominent privacy warning or explicit consent step. In the context of a 'real-human' skill focused on user profiling, that creates a meaningful risk of covert sensitive inference, overcollection, and downstream misuse of psychological or personal data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all instructional content in a single language and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The entire skill reference is presented only in Chinese, which may amount to a language-policy constraint if the skill expects or forces that locale without user opt-in. The file does not state that the skill is region-specific or provide any language choice mechanism.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.