Back to skill

Security audit

AI心理疗愈专家

Security checks across malware telemetry and agentic risk

Overview

This is a document-only emotional support skill with disclosed safety boundaries, but users should be aware it may activate on broad everyday distress phrases.

Before installing, understand that this skill may activate for ordinary emotional or life-decision language and respond in a reflective support style. It is not professional mental health care; users in crisis, with self-harm thoughts, violent intent, psychosis-like symptoms, or impaired daily functioning should use professional or emergency support instead of relying on the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger conditions are broad enough to match common, low-severity phrases such as '想找人聊聊' or general uncertainty, which can cause the skill to activate outside clearly therapeutic contexts. In a mental-health-adjacent skill, over-triggering is risky because it may steer ordinary conversations into quasi-counseling behavior without clear user intent, increasing the chance of inappropriate guidance or missed escalation when real risk is present.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list contains very broad, common phrases such as '焦虑', '心里乱', and '想找人聊聊' that can appear in ordinary conversation without explicit intent to invoke a mental-health-style skill. In this context, unintended activation is more sensitive than usual because the skill operates in a psychological support domain, so accidental invocation could steer users into emotionally influential guidance when they did not ask for it.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The file includes a high-intensity exercise ('主动想象') that can destabilize users, and while the document has general stop conditions and says it should only be used when the user is stable with support, it does not give an explicit, localized warning at the exercise itself to pause and seek professional help if distress escalates. In a mental-health-oriented skill, deep imagery/dialogue exercises can amplify dissociation, rumination, or crisis symptoms, so insufficiently prominent warnings increase the chance of harm from misuse or overextension.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.