Back to skill

Security audit

Digital Persona

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed markdown-only skill for drafting deceased-person persona files, with real impersonation-adjacent ethics risks but no hidden code, credential access, or unsafe execution.

Install only if you intentionally want a workflow for creating speculative deceased-person personas. Treat generated personas as simulations, not authentic statements from the person, and avoid using them for living people, deception, harassment, legal signatures, or claims that are not clearly sourced.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README explicitly promotes creating deployable digital personas of real and deceased people, including examples like 'bring historical figures back to life' and 'ready for agent deployment,' without any warning about consent, privacy, defamation, impersonation, or reputational harms. In this context, the omission is security-relevant because it normalizes high-risk identity simulation and lowers friction for misuse such as deceptive impersonation, emotional manipulation, or unauthorized replication of a real person's likeness and behavior.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list includes broad phrases such as generic AI-roleplay and persona terms that can match ordinary user requests, causing the skill to activate outside its narrow intended use. In this context, unintended activation is more concerning because the skill is designed to reconstruct deceased persons' identities and speaking styles, which can lead to privacy, consent, impersonation, or emotional-harm risks if invoked accidentally.

Vague Triggers

Low
Confidence
85% confidence
Finding
The activation phrases are broad enough that ordinary requests like 'simulate X' or 'make an AI of X' could unintentionally trigger persona mode without clear exclusion conditions or consent checks. In this skill, that matters more because it is designed to reconstruct deceased persons' identities, which can amplify impersonation, consent, and misuse risks even if the example itself is not directly instructing harmful actions.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The file strongly fixes a specific Chinese-language presentation and stylistic framing without any user preference check, which can override user locale expectations and reduce transparency about how the agent should respond. While not a classic security flaw, rigid forced style can increase the risk of deceptive immersion in a persona skill by making the agent prioritize character fidelity over user intent or safety clarifications.

Static analysis

No suspicious patterns detected.