Back to skill

Security audit

感通荣格(Gantong)

Security checks across malware telemetry and agentic risk

Overview

This is a document-only emotional-support skill with broad therapeutic framing, but it discloses its purpose, includes crisis boundaries, and shows no hidden code or data access.

Install only if you want a non-clinical reflective companion for emotional support, dreams, meaning, and life transitions. It should not be used for emergencies, self-harm, suicidality, violence risk, psychosis, diagnosis, or as a substitute for a licensed mental-health professional.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The manifest description and default prompts use very broad emotional-support language such as feeling unsettled and wanting someone to talk to. That makes the skill easy to activate from ordinary conversation, increasing the chance it is invoked outside the user's clear intent and begins providing quasi-therapeutic guidance in sensitive mental-health contexts. In this skill, accidental routing is more concerning because the domain involves emotional distress, meaning, and psychological interpretation.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The quick prompts are common, ambiguous statements about distress, dreams, and emptiness that many users could say in normal conversation. Because they lack scope limits or safety qualifiers, they may trigger this specialized mental-health-style skill unintentionally and steer vulnerable users into deep psychological framing without explicit consent. The skill context makes this risk higher than in a generic journaling tool because it presents itself as a healing therapist and invites existential exploration.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The manifest advertises broad emotional-support and existential prompts such as feeling unsettled, recurring dreams, and questioning life's meaning, but it does not define visible scope limits, crisis handling, or escalation boundaries in the activation examples. In a mental-health-adjacent skill, this can draw users into relying on the agent for sensitive psychological support, including potentially high-risk situations, without clearly signaling that the tool is not a licensed clinician or emergency resource.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger language is very broad and overlaps with ordinary conversation, so the skill may activate unintentionally for users casually mentioning stress, dreams, relationships, or life direction. In a mental-health-adjacent skill, mistaken activation is more concerning because it can steer normal chats into pseudo-therapeutic guidance and increase the chance of inappropriate handling of vulnerable users.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation conditions cover broad categories like anxiety, emptiness, relationships, career choices, and self-exploration without precise boundaries, making over-triggering likely. Because this skill presents itself as a healing expert, ambiguous routing can inappropriately engage users in sensitive psychological guidance, including users in crisis or users seeking ordinary advice, which raises safety and misclassification risk.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation scope is extremely broad, covering common emotional support, life meaning, relationships, anxiety, career decisions, and existential distress. In a routing system, this can cause the skill to intercept many ordinary user requests and place them into a quasi-therapeutic flow, which is especially risky because the skill operates in a mental-health-adjacent domain where misrouting can delay safer general support or crisis escalation.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This README markets the skill as an AI 'healing' and deep psychological companion for anxiety, emptiness, meaninglessness, dreams, and existential distress, but it does not clearly warn that it is not a crisis service, not a licensed clinician, and not suitable for emergencies. In a mental-health context, that omission can cause vulnerable users to over-rely on the skill during suicidality, severe depression, psychosis, or other acute situations, delaying real-world care when time-sensitive intervention is needed.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation criteria are extremely broad and match common emotional or reflective language such as feeling low, wanting to talk, relationship confusion, or career uncertainty. This can cause the skill to activate unintentionally during ordinary conversation and steer users into quasi-therapeutic framing without explicit consent, which is especially risky in a mental-health context.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The sample trigger phrase '最近心里有些乱,想找个人聊聊,可以陪陪我吗?' is highly generic and could appear in many normal chats. Using such a broad example increases the chance of accidental routing into a therapeutic persona, which may change tone, assumptions, and advice style in sensitive situations without the user's informed choice.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The description defines a fixed Chinese-language therapeutic persona without mentioning user preference, language selection, or opt-in. While not inherently malicious, forcing a specific persona and language can override user expectations and reduce transparency, particularly in sensitive mental-health interactions where informed consent and clarity matter.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation criteria are broad enough to trigger on common discussions about feelings, relationships, anxiety, or life direction, which risks routing users into a quasi-therapeutic persona in situations where they did not explicitly seek mental-health-style support. In this context, overbroad activation is more dangerous because the skill is designed for emotionally vulnerable users and may influence sensitive conversations, increasing the chance of inappropriate reliance or boundary crossing.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The top-level description does not prominently warn that crisis situations require immediate professional or emergency help, even though the skill operates in a mental-health-adjacent domain. That omission is dangerous because users in acute distress may engage the skill first and misinterpret it as suitable support during self-harm, suicide, violence, or psychiatric emergencies.

Vague Triggers

Low
Confidence
81% confidence
Finding
The manifest describes very broad mental-health and life-guidance use cases, including emotional distress, meaninglessness, relationship issues, and major life transitions, without precise activation boundaries or exclusions. In a wellness/psychological-support skill, this can cause the agent to be invoked in higher-risk situations that may drift into crisis support, quasi-therapy, or other sensitive guidance beyond safe scope, increasing the chance of harmful or inappropriate responses.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.