Back to skill

Security audit

Digital Persona

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for creating deceased-person persona files, with ethical impersonation risks but no hidden code, credential access, or unsafe install behavior found.

Install only if you intend to create clearly labeled fictionalized or analytical personas. Use public and appropriate sources, avoid private or non-consensual details, do not present generated personas as the real person or as endorsements, and require explicit user intent before switching into a persona mode.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger list is broad and includes generic phrases like '做个XX的AI', 'digital persona', and '已故人物', which can cause the skill to activate unintentionally for loosely related user requests. In this context, unintended invocation is more dangerous because the skill facilitates creation of deceased-person simulations, a sensitive capability that can enable impersonation-like outputs, reputational harm, or emotionally manipulative interactions without clear user intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill description promotes 'digital immortality' for deceased persons without any warning about ethical, emotional, consent, or misuse risks. Because the skill is specifically designed to recreate recognizable deceased individuals in an interactive form, the absence of a warning lowers user awareness and increases the chance of harmful or deceptive use.

Vague Triggers

Low
Confidence
88% confidence
Finding
The activation examples include short, natural-language trigger phrases such as “模拟乔布斯” and “以乔布斯的身份” without clear exclusion or confirmation rules. In a conversational system, broad triggers can cause unintended persona activation, leading the agent to impersonate a deceased public figure when the user may only be discussing that person rather than requesting roleplay.

Static analysis

No suspicious patterns detected.