Back to skill

Security audit

Yangmou

Security checks across malware telemetry and agentic risk

Overview

The skill is transparent about being a business-strategy workflow, but it repeatedly teaches pressure and lock-in tactics that can steer AI toward manipulative advice.

Install only if you intentionally want an adversarial strategy-analysis skill and can keep it bounded to ethical, lawful negotiation. Do not allow it to auto-trigger for everyday business, customer, or coworker advice; require explicit opt-in and reject outputs that exploit fear, dependency, internal politics, hidden switching costs, or emotional vulnerability.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (15)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill instructs the agent to read local reference files and invoke `scripts/retrieve.py`, but the manifest shown does not declare corresponding permissions. Undeclared file-read/code-like capabilities weaken transparency and policy enforcement, and can cause an agent to access local content beyond what a user expects.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger guidance is broad enough that ordinary user requests about negotiation, pricing, marketing, or workplace problems could invoke the skill unintentionally. In this skill's context, unintended activation is more concerning because the workflow is explicitly designed to generate coercive-style '对方明知是坑也不得不跳' strategies, which can steer benign conversations toward manipulative advice without a clear user opt-in.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example utterances are common, everyday business questions and lack strong boundaries distinguishing normal advisory use from activation of a specialized influence/manipulation workflow. Because the skill presents itself as applicable across many interpersonal and commercial disputes, these examples increase the chance of silent or surprising activation, causing the model to adopt the skill's framing and escalation logic in contexts where users did not explicitly request it.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The top-level description uses broad triggers such as helping users 'win' negotiations, customers, competition, and other common business situations. Overbroad activation increases the chance the skill is invoked in normal conversations where manipulative guidance is neither requested nor appropriate, expanding exposure to harmful outputs.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The '何时使用' section activates on vague phrases like solving a difficult situation or wanting a better strategy, which overlap heavily with ordinary business assistance. This ambiguity can route benign requests into a coercive framework centered on counterparty leverage, increasing misuse risk.

Natural-Language Policy Violations

High
Confidence
76% confidence
Finding
The skill content is written to operate in Chinese and does not indicate language adaptation based on user preference. Forcing a locale without opt-in can cause misunderstandings, reduce informed consent, and make risky strategic advice harder for some users to evaluate correctly.

Ssd 4

High
Confidence
97% confidence
Finding
The description explicitly frames the goal as producing strategies where the target knows the setup but is still compelled to comply, including 'locking in' customers, pressuring prices, and making competitors or counterparts unable to resist. This is a coercive persuasion design pattern that operationalizes manipulation rather than neutral analysis, and the surrounding business context broadens the set of plausible real-world victims.

Ssd 4

High
Confidence
98% confidence
Finding
The four-round questioning flow systematically collects the counterparty's fears, decision structure, weaknesses, leverage points, and escalation tolerance. Building this manipulation profile enables the agent to tailor pressure tactics that exploit psychological and structural constraints, which is dangerous even if the text claims not to use deception.

Ssd 4

High
Confidence
98% confidence
Finding
The analysis and output stages direct the model to convert discovered constraints into a 'locking mechanism,' design public signaling/pressure ('明牌/造势'), and plan defenses against resistance. That is a concrete recipe for coercive steering: it turns knowledge of fears and rules into pressure architectures that reduce the target's practical ability to choose freely.

Ssd 4

High
Confidence
95% confidence
Finding
This section explicitly teaches '反客为主'—entering as a harmless collaborator, gradually inserting into key processes, and ultimately seizing control. In an agent skill, that is dangerous because it can normalize covert privilege escalation, insider manipulation, or social-engineering playbooks that an AI could adapt to real organizational targets.

Ssd 4

High
Confidence
94% confidence
Finding
This sequence describes a classic dependency-then-lock-in pattern: first create reliance through free trial or openness, then impose switching costs or control in a second step. In skill context, this is risky because it operationalizes manipulative retention and coercive leverage that can be transferred to sales, product, negotiation, or internal influence scenarios.

Ssd 4

Medium
Confidence
89% confidence
Finding
This entry promotes giving first or lowering the target's guard, then using that reduced resistance to secure strategic advantage later. Even when phrased as strategy, it creates a reusable social-engineering pattern: build trust instrumentally, then exploit the trust asymmetry for control or leverage.

Ssd 4

Medium
Confidence
93% confidence
Finding
This section explicitly teaches elicitation and influence tactics such as probing, praise-then-control, emotional timing, and relationship-binding to extract intentions and steer targets while preserving plausible openness. In an agent skill context, these patterns can be repurposed for manipulative social engineering against customers, coworkers, or internal stakeholders under the guise of legitimate strategy advice.

Ssd 4

Medium
Confidence
95% confidence
Finding
These examples normalize progressive lock-in: offering trials, gradual insertion into workflows, or linked tactics that make later exit harder and increase dependency over time. In a skill designed to operationalize strategy across sales, management, and negotiation, that framing materially increases the chance of an agent recommending coercive retention or dark-pattern behavior.

Ssd 4

Medium
Confidence
97% confidence
Finding
The modern-cases section repeatedly presents free offers, gifts, symbolic rewards, authority leverage, coalition pressure, and internal-friction tactics as deliberate hooks to bind targets into the operator's preferred outcome. Because the broader skill promises '对方明知却不得不就范' outcomes, these patterns are more dangerous here than in neutral historical analysis: they function as reusable playbooks for coercive persuasion and organizational manipulation.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.