other
- Location
SKILL.md:61- Finding
Automatic Persistent User Profiling Without Prior Opt-In Consent
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is meant for personalization, but it directs agents to automatically build persistent user profiles that may include sensitive personal and psychological information without a clear opt-in step.
Review this skill carefully before installing. It has no executable malware indicators, but it is designed to persistently model users across conversations. Only use it where users have clearly opted in, can inspect and delete all profile copies, and understand that sensitive inferences may be stored unless the skill is tightened.
SKILL.md:61Automatic Persistent User Profiling Without Prior Opt-In Consent
references/extraction-methods.md:47Speculative Personal and Psychological Inferences Can Be Persisted as High-Confidence Non-Sensitive Data
SKILL.md:93Sensitive Profile Storage Is Described as Encrypted Without Any Encryption Implementation
The skill describes automatically creating and updating per-user profile files from conversations but does not clearly warn users that persistent profiling will occur. This is dangerous because users may share sensitive personal, relational, or behavioral information without informed consent, and the storage persists across sessions.
The trigger phrases are broad enough to match common conversational topics like personality analysis or understanding a person, which can cause the skill to activate unexpectedly. In this skill's context, unintended invocation is more dangerous because activation leads to profiling and persistence of personal data, increasing privacy risk without explicit user intent.
The instructions explicitly direct the system to persistently collect, extract, and store user information after each interaction. Even though the document mentions privacy and authorization in principle, the operational workflow normalizes continuous profiling, which can capture sensitive data and create long-lived dossiers vulnerable to misuse or unauthorized access.
The skill encourages broad logging of identity, cognition, emotions, behaviors, social relationships, and ongoing goals into profile and memory files. This breadth makes the skill more dangerous than ordinary personalization because it systematizes detailed person-modeling across multiple sensitive domains, enabling invasive profiling and increasing harm if exposed, inferred incorrectly, or reused beyond the user's expectations.
The file says health, financial, family-conflict, and psychological information require authorization and should not be proactively recorded, but the later automatic-extraction example labels clear mental-health distress and life-status data as non-sensitive. That contradiction can cause the skill to silently classify and retain sensitive personal inferences without consent, especially in a skill explicitly designed for human modeling and profiling.
This guidance endorses automatic extraction of emotion, life situation, and latent needs from free-text user input without a prominent privacy warning or explicit consent step. In the context of a 'real-human' skill focused on user profiling, that creates a meaningful risk of covert sensitive inference, overcollection, and downstream misuse of psychological or personal data.
This markdown file presents all instructional content in a single language and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation.
The entire skill reference is presented only in Chinese, which may amount to a language-policy constraint if the skill expects or forces that locale without user opt-in. The file does not state that the skill is region-specific or provide any language choice mechanism.
No suspicious patterns detected.