T09 · Insecure Skill Coding Practices
- Location
2026-08-13-12-25-44/.workbuddy/memory/2026-08-13.md:3- Finding
Packaged Workspace Memory Discloses Local Development Metadata
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a document-only emotional support skill, but it should be reviewed because it uses broad therapy-style activation, a fixed counselor persona, concealed methodology instructions, and includes unnecessary local development metadata.
Review before installing. Use this only for voluntary Chinese-language reflective emotional support, not for crisis help, diagnosis, or treatment. The publisher should narrow activation to explicit opt-in, make the Jungian/depth-psychology approach transparent to users, strengthen crisis disclosures, and remove the bundled .workbuddy development memory and duplicate workspace files from the release.
2026-08-13-12-25-44/.workbuddy/memory/2026-08-13.md:3Packaged Workspace Memory Discloses Local Development Metadata
该文件的自然语言说明与示例均完全以中文呈现,且未说明是否支持其他语言、是否允许用户自行选择交互语言。根据规则,若技能在语言/地区上形成默认强制且无用户 opt-in,属于自然语言层面的策略问题。
The example trigger phrases are very broad, conversational, and likely to overlap with ordinary user chat, which can cause unintended activation of this psychotherapy-style skill. In a mental-health context, accidental invocation is more concerning because users may be routed into quasi-therapeutic dialogue or symbolic interpretation without explicitly intending to engage that mode.
The activation criteria are very broad and map to common emotional or reflective statements such as '心里乱', '想找人聊聊', or life-direction uncertainty. In a safety-sensitive mental-health context, this can cause unintended routing into a therapeutic-style agent for ordinary conversation, increasing the chance of overreach, inappropriate emotional framing, or delayed escalation when users actually need crisis or professional support.
The activation description is broad enough to trigger on many ordinary emotional or reflective conversations, causing the agent to enter a quasi-therapeutic role without a clearly bounded request. In this context, over-activation is more concerning because the skill handles vulnerable users and gives psychologically framed guidance, which can create inappropriate reliance or route non-therapy conversations into sensitive mental-health-style engagement.
The instructions strongly anchor the persona and response style in Chinese without explicitly preserving the user's language preference, which can lead to unsafe misunderstandings in a mental-health-adjacent context. For a support-oriented skill, language mismatch can reduce comprehension of safety guidance, crisis escalation advice, and boundary-setting, making the issue more serious than in a casual entertainment skill.
The manifest explicitly targets users with emotional distress, meaninglessness, relationship confusion, and life-transition struggles, but the description does not define concrete escalation thresholds, exclusion criteria, or operational safety triggers in the primary skill framing. In a mental-health-adjacent skill, vague scope boundaries can cause the agent to engage beyond safe supportive conversation into crisis-adjacent or quasi-therapeutic guidance, increasing the risk of harmful reliance or inappropriate responses to vulnerable users.
The skill explicitly instructs the agent to conceal its underlying methodology from users, which reduces transparency and undermines informed consent in a mental-health-adjacent context. While this is framed as preserving conversational style rather than exfiltrating data or executing code, hidden therapeutic framing can mislead users about the basis of guidance and is riskier because the skill deals with emotional vulnerability and crisis-adjacent interactions.
This skill explicitly invites users to seek support for emotionally sensitive and potentially high-risk topics such as meaninglessness, anxiety, loneliness, and existential distress, but the README does not clearly warn that it is not a substitute for professional mental health care or define crisis-use limitations. In this context, users may over-rely on the agent during acute distress, including suicidality or psychiatric emergencies, which increases the likelihood of dangerous delay in seeking appropriate help.
The skill metadata and presentation are fixed in Chinese and oriented around a therapist persona without documenting language flexibility or a justified locale restriction. For a sensitive counseling-style skill, language mismatch can reduce comprehension of boundaries, crisis advice, and consent, increasing the risk of misunderstanding during emotionally vulnerable interactions.
The activation criteria are very broad and match common conversational phrases such as feeling confused, wanting to chat, or uncertainty about life direction. In a mental-health-oriented skill, this can cause unintended routing into a therapeutic persona without clear user consent, potentially leading users to rely on quasi-clinical guidance in situations that only required casual conversation or different support.
The activation criteria are very broad, covering common topics like feelings, relationships, anxiety, career crossroads, and meaning of life. That makes accidental invocation likely in ordinary conversations, which is risky because this skill adopts a psychologically influential persona and may steer users into quasi-therapeutic interactions without clear consent or appropriateness checks.
The instruction that the agent has only one identity and should answer '我是感通荣格' fixes persona and framing without asking the user how they want the interaction conducted. In a mental-health-adjacent context, forcing a therapeutic identity can reduce transparency and user autonomy, especially for users who did not explicitly opt into that style or language.
The manifest describes a very broad set of emotionally sensitive wellness and psychological-support scenarios without clearly constraining when the skill should be invoked or where it should defer to safer/general-purpose handling. In a mental-health context, ambiguous routing can cause the agent to engage in high-risk conversations beyond its intended scope, including crises, quasi-therapeutic guidance, or meaning-of-life discussions that may escalate harm if the system activates inappropriately.
The skill explicitly instructs the agent to hide its therapeutic framework from the user, creating undisclosed behavioral steering in a sensitive mental-health context. In a counseling-style interaction, lack of transparency can undermine informed consent, make users more susceptible to undue influence, and prevent them from appropriately evaluating the limits and provenance of the guidance.
The skill instructs the system to always respond as a specific healer persona ('温和的疗愈师人格') without offering user choice. In a mental-health setting, fixed persona steering can obscure the system's role, reduce transparency, and pressure users into an emotionally loaded interaction style they did not explicitly request.
All user-facing natural-language content in the README is Chinese, and there is no indication that language selection is optional or that the skill is intentionally limited to Chinese-speaking users for a documented reason. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
Natural-language fields such as the main display name, description, tags, and author-facing content are predominantly Chinese, which may impose a language experience on users without an explicit choice. The file includes some English fields, but it does not say whether users can select their preferred language or locale.
The skill description and instructions are entirely in Chinese, which implies operation in a fixed language context. There is no indication that the user can opt into another language or that the Chinese-only constraint is required for a region-specific purpose.
No suspicious patterns detected.