Back to skill

Security audit

my skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a chat-based personality profiler that has no malware-like installer, but it asks for sensitive psychological judgments, external screenshot upload, and manipulation/impersonation-style outputs without enough safeguards.

Review before installing. Use this only on conversations you are allowed to analyze, avoid uploading screenshots with private or third-party data, and treat any personality or psychological claims as speculative. The manipulation, dark-trait, and imitation sections are the main reasons this should receive extra scrutiny rather than automatic trust.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:26
Finding

Uncontrolled External Upload of Sensitive Chat Screenshots

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match ordinary requests like '分析一下这个人' or '分析聊天记录', which can cause the skill to activate in situations the user did not specifically intend. Because this skill performs sensitive psychological profiling, over-triggering increases the chance of unsolicited inference, privacy intrusion, and analysis of third-party personal data without clear consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is designed to infer personality traits, psychological needs, manipulativeness, attachment style, and related sensitive attributes from chat logs, but it provides no upfront warning about the sensitivity, uncertainty, or consent implications of such profiling. This is dangerous because users may upload private conversations involving non-consenting third parties and receive speculative mental-health-like inferences presented with undue authority.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template explicitly asks for advice on what to say or do to trigger the target’s '雷点' and gain their attention, which turns a personality-analysis skill into a social manipulation aid. In the context of analyzing private chat records and producing psychological portraits, this materially increases the risk of harassment, coercive influence, or emotionally exploitative targeting of a real person.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all methodology and instructions exclusively in Chinese, with no indication that the user can opt into another language. The policy requires flagging language or locale constraints when a skill effectively forces a specific language without user choice or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire report template is written in Chinese and assumes output in that language, with no indication that users may choose another language or opt in to Chinese output. Under the language/locale policy rule, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The template instructs the model to produce detailed psychological profiling, trait scoring, and dark-trait analysis without warning about uncertainty, sensitivity, or potential harm. Because the skill operates on chat records and infers intimate attributes about a person, the lack of safeguards makes overconfident, invasive, and potentially defamatory outputs more likely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template requires default speculation about '黑化可能' and at least three possible '邪恶倾向,' even when evidence may be weak or absent. This encourages ungrounded harmful inferences, stigmatizing labels, and overclaiming psychological danger beyond the stated purpose of style/personality analysis.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Including a 'style imitation guide,' catchphrase list, and simulated replies extends the skill from analysis into impersonation-enabling behavior. In a skill built from chat-log analysis, this can help users mimic a real person’s tone or identity for deception, social engineering, or non-consensual imitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.