Back to skill

Security audit

雄韬识人辨人 - 老板阅人笔记 The Ren Skill

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only skill is transparent about its people-reading purpose, but it gives practical hiring and partnership guidance based on face, posture, and speculative personality signals.

Review this skill carefully before installing. It does not appear to run code or access your data, but it may encourage users to make hiring, promotion, firing, partnership, or customer-risk judgments from appearance and subjective behavior cues. Use only for reflective discussion or bias-awareness prompts, not as a decision tool for people’s jobs, contracts, or opportunities.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
Although the file includes a disclaimer that the model is not scientifically validated, it still provides operational guidance for assessing candidates' emotional stability, honesty, control, and empathy in business and hiring contexts. These are sensitive, high-risk inferences that can drive unfair or discriminatory decision-making, especially because the framework links facial cues and subjective observations to job suitability without a strong fairness warning or prohibition on employment decisions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The behavioral test section instructs evaluators to deliberately provoke, delay, and interrupt a person to observe reactions, which normalizes deceptive and manipulative interactions during assessment. In hiring or business screening contexts, these tactics can create unfair pressure, distort outcomes, and expose organizations to ethical, legal, and reputational harm, especially when combined with subjective personality judgments.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
Although the file contains an internal disclaimer, the skill metadata and surrounding content still position the framework for interview evaluation, hiring, partnership judgment, and other business decisions. Missing a prominent end-user warning at the skill level increases the chance that users will rely on speculative physiognomy and unvalidated personality inference in consequential decisions.

Natural-Language Policy Violations

Low
Confidence
98% confidence
Finding
The handbook repeatedly encourages evaluating employees, customers, partners, and other business counterparts based on facial features, eye movements, posture, gait, and other appearance-linked traits. Even though it includes disclaimers, it still operationalizes physiognomy into hiring, management, and trust decisions, which can enable discriminatory profiling, pseudoscientific decision-making, and unfair exclusion of people based on protected or health-related traits. The Chinese-only presentation without language choice is a secondary issue; the primary risk is that the skill provides actionable biased assessment criteria for real-world business decisions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This section recommends using speculative behavioral and stress cues in hiring, partnership screening, and negotiation to infer hidden information, despite the file only offering a general scientific caveat. In a high-stakes employment and business context, users may over-trust these cues and make discriminatory or unfair decisions based on weak proxies rather than validated assessment methods.

Missing User Warnings

High
Confidence
98% confidence
Finding
This section directly links facial features, wrinkles, mouth shape, and '常态表情' with long-term emotional states and then instructs users to apply those observations in interviews and employee evaluation. That encourages appearance-based personnel judgment, a particularly sensitive and harmful use case because it can encode physiognomy-style bias, lead to discriminatory treatment, and falsely present facial appearance as evidence of character or workplace suitability.

Ssd 4

Medium
Confidence
95% confidence
Finding
The document explicitly walks users from a nominal disclaimer into a practical workflow for classifying people, validating face-based signals, applying veto checks, and making hiring or business decisions. This is dangerous because it operationalizes appearance-based profiling in high-stakes contexts, encouraging biased, discriminatory, and unreliable judgments while giving them a structured veneer of rigor.

Ssd 4

Medium
Confidence
97% confidence
Finding
These lines present a step-by-step decision process that uses face-based typing, cross-validation by physiognomic signals, veto scanning, and final role decisions. In context, this makes the skill more dangerous because it turns speculative and unvalidated appearance judgments into actionable screening logic for employment and partnership decisions.

Static analysis

No suspicious patterns detected.