T09 · Insecure Skill Coding Practices
- Location
SKILL.md:26- Finding
Uncontrolled External Upload of Sensitive Chat Screenshots
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a chat-based personality profiler that has no malware-like installer, but it asks for sensitive psychological judgments, external screenshot upload, and manipulation/impersonation-style outputs without enough safeguards.
Review before installing. Use this only on conversations you are allowed to analyze, avoid uploading screenshots with private or third-party data, and treat any personality or psychological claims as speculative. The manipulation, dark-trait, and imitation sections are the main reasons this should receive extra scrutiny rather than automatic trust.
SKILL.md:26Uncontrolled External Upload of Sensitive Chat Screenshots
The trigger phrases are broad enough to match ordinary requests like '分析一下这个人' or '分析聊天记录', which can cause the skill to activate in situations the user did not specifically intend. Because this skill performs sensitive psychological profiling, over-triggering increases the chance of unsolicited inference, privacy intrusion, and analysis of third-party personal data without clear consent.
The skill is designed to infer personality traits, psychological needs, manipulativeness, attachment style, and related sensitive attributes from chat logs, but it provides no upfront warning about the sensitivity, uncertainty, or consent implications of such profiling. This is dangerous because users may upload private conversations involving non-consenting third parties and receive speculative mental-health-like inferences presented with undue authority.
The template explicitly asks for advice on what to say or do to trigger the target’s '雷点' and gain their attention, which turns a personality-analysis skill into a social manipulation aid. In the context of analyzing private chat records and producing psychological portraits, this materially increases the risk of harassment, coercive influence, or emotionally exploitative targeting of a real person.
This markdown file presents all methodology and instructions exclusively in Chinese, with no indication that the user can opt into another language. The policy requires flagging language or locale constraints when a skill effectively forces a specific language without user choice or documented justification.
The entire report template is written in Chinese and assumes output in that language, with no indication that users may choose another language or opt in to Chinese output. Under the language/locale policy rule, forcing a specific language without user choice is a natural-language policy violation.
The template instructs the model to produce detailed psychological profiling, trait scoring, and dark-trait analysis without warning about uncertainty, sensitivity, or potential harm. Because the skill operates on chat records and infers intimate attributes about a person, the lack of safeguards makes overconfident, invasive, and potentially defamatory outputs more likely.
The template requires default speculation about '黑化可能' and at least three possible '邪恶倾向,' even when evidence may be weak or absent. This encourages ungrounded harmful inferences, stigmatizing labels, and overclaiming psychological danger beyond the stated purpose of style/personality analysis.
Including a 'style imitation guide,' catchphrase list, and simulated replies extends the skill from analysis into impersonation-enabling behavior. In a skill built from chat-log analysis, this can help users mimic a real person’s tone or identity for deception, social engineering, or non-consensual imitation.
No suspicious patterns detected.