Back to skill

Security audit

鬼谷子72术

Security checks across malware telemetry and agentic risk

Overview

This is a strategy and persuasion skill, but it includes coercive influence tactics and unnecessary permissions that warrant careful review before installation.

Review this before installing. Remove the git mutation permissions and narrow or remove broad triggers. Treat the coercive persuasion, bribery-like, infiltration, and competitor-disruption material as unsafe for real business, finance, hiring, or negotiation use unless it is rewritten as prohibited behavior or defensive awareness only.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (49)

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill is described as a persuasion/strategy cognition tool, but it is granted local git mutation capabilities (`git init`, `git add`, `git rm`) that can alter repository state. Those permissions are not clearly required for the declared purpose and could be abused to stage, remove, or initialize repository contents in ways the user does not expect.

Context-Inappropriate Capability

Low
Confidence
83% confidence
Finding
Allowing `WebFetch` to a specific external domain introduces outbound network access that is not justified by the skill's stated advisory role. Even when scoped to one domain, this can enable unneeded data exfiltration, remote content retrieval, or hidden dependency on an external service outside the user's expectations.

Context-Inappropriate Capability

Low
Confidence
80% confidence
Finding
General `WebSearch` access exceeds the capabilities disclosed by a strategy/persuasion skill and broadens the agent's ability to access external information sources. This can increase risk of unintended data sharing, prompt-driven reconnaissance, or behavior drift beyond the local cognitive-advisory purpose advertised to users.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill presents an ethics gate that ostensibly refuses manipulation, but the substantive guidance later normalizes tactics such as obligation-building, lock-in, pressure through third parties, and emotional leverage. This contradiction is dangerous because it can bypass user and operator trust checks: the safety framing lowers scrutiny while the operational content still equips coercive influence behavior.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The statement that 'influence is not manipulation' is directly undermined by later recommendations for '无法轻易退出' structures, public-commitment lock-in, sunk-cost pressure, and externally applied pressure. This mismatch makes the safety claim misleading and increases the likelihood that harmful tactics are treated as approved best practice.

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
This section explicitly advises creating structures that make a target unable to easily withdraw, using public commitments, sunk costs, and interlinked interests to 'lock' them in. That is a coercive capability rather than ordinary business communication support, and it can be used to pressure counterparties into decisions they would not freely sustain.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill recommends deliberate emotional activation as an influence tool to break rational stalemate and pressure the other party into disclosing reasons or changing position. Even if framed as '适度,' this trains users to instrumentalize emotion to override independent judgment, which is not justified by an ethical persuasion assistant.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
This section explicitly advocates placing personnel inside an opponent’s core to gain advantage and cause internal disintegration. In a business/finance strategy skill, that goes beyond abstract cognition or historical reference and can operationalize covert infiltration, insider abuse, or unlawful competitive intelligence, making misuse plausible.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The content recommends using money or benefits to break apart an opponent’s internal structure, which maps directly to bribery-like inducements and corrupt manipulation. Within an advisory skill for negotiation, competition, and finance, this can normalize illegal conduct and provide users with a strategic frame for interfering with third parties through improper payments or coercive incentives.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
This reference file includes tactics such as bribery, rumor manipulation, internal sabotage, and covert intelligence activities framed as usable strategic methods, not purely as historical analysis or ethics warnings. In a business/finance decision-support skill, that creates a material risk that users or downstream agents operationalize illegal or deceptive conduct under the guise of strategy guidance.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The document explicitly recommends '潜入对方核心' and describes infiltration of an opponent's core to gain advantage, which is covert intrusion behavior. In the stated context of business and finance strategy support, this is especially dangerous because it can normalize espionage, insider recruitment, or unauthorized access as acceptable competitive practice.

Intent-Code Divergence

Low
Confidence
86% confidence
Finding
Although the document labels some entries as warnings, it still presents them within the same numbered strategy system with applicability framing, which weakens the warning and preserves their instructional value. That contradiction can lead users to treat harmful methods like rumor exploitation as endorsed options rather than prohibited or cautionary material.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
This reference material includes tactics such as bribery, internal subversion, and manipulative deception that can directly enable unethical or illegal conduct beyond ordinary strategic analysis. In a skill positioned for business, finance, negotiation, and intelligence-style decision support, presenting these as usable methods materially increases the risk that the agent will normalize or recommend harmful real-world actions.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The text explicitly recommends placing personnel inside an opponent's core organization to gain advantage, which is a covert infiltration tactic with obvious misuse potential. In this skill context, that is especially dangerous because it can be operationalized as corporate espionage, trade-secret theft, or unlawful interference under the guise of strategy advice.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
This section explicitly recommends '潜入对方核心' and frames infiltration of an opponent's core organization for advantage as a usable strategy. In a business/finance advisory skill, that crosses from abstract strategy into operational guidance for covert subversion, competitive intelligence abuse, and potentially illegal insider access, making misuse foreseeable and contextually dangerous.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
This passage endorses using money or material incentives to destabilize an opponent internally ('用金钱利益去瓦解对方内部'), which maps to bribery-like payoff manipulation and corrupt influence. In a commercial strategy skill, that can normalize unlawful conduct such as bribery, inducement of disloyalty, trade-secret targeting, or procurement corruption.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, generic expressions such as '我处于劣势' and '没办法了' that can appear in ordinary conversation, making accidental invocation likely. In a skill focused on competitive strategy, unintended activation can steer benign discussions toward manipulation-oriented framing or unnecessary strategic advice, increasing misuse risk even without explicit malicious content.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad everyday terms such as '合作', '怎么招人', and '谁可以帮我', which can cause the skill to activate in many ordinary conversations outside its intended high-stakes strategy context. Because this skill contains guidance on alliance manipulation, competitor coalition weakening, and adversarial interpersonal tactics, accidental invocation can steer benign user requests toward manipulative or ethically risky advice.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger conditions include broad, common business terms such as '竞争太激烈了', '找不到差异化', and '商业模式创新', which are likely to appear in ordinary conversation outside the user's intent to invoke this specific skill. This can cause unintended activation and steer the assistant into competitive strategy framing when the user may only be discussing general business concerns, increasing the risk of overreach or misaligned advice.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes broad, common terms such as '这笔交易怎么谈', '对方是什么意图', and generic negotiation-related keywords that can match ordinary conversation outside the intended finance-specific scope. This can cause unintended activation of a high-influence negotiation skill, injecting strategic or manipulative framing into unrelated contexts and increasing the chance of unsafe or inappropriate guidance being surfaced.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad everyday expressions such as '怎么说服' and '他不听我的,' making this skill likely to activate in many ordinary conversations. Because the skill contains coercive influence content, accidental activation increases exposure to manipulative tactics in contexts where users may have intended benign advice.

Natural-Language Policy Violations

High
Confidence
97% confidence
Finding
The content promotes pressure and entrapment tactics that constrain a target's freedom to exit rather than merely helping with presentation, negotiation, or language choice. In a skill intended for broad business use, this materially increases the risk of abusive deployment against colleagues, customers, counterparties, or subordinates.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are very broad generic prompts such as '帮我分析一下', '怎么看', and '判断', which overlap heavily with ordinary conversation. This can cause unintended activation of the skill in unrelated contexts, leading the agent to apply strategic or adversarial framing when the user did not explicitly request it. In a skill focused on intelligence analysis, accidental invocation increases the chance of over-interpretation, misleading guidance, or unnecessary collection/structuring of sensitive contextual information.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are extremely broad and map to ordinary investing discussion such as buying, selling, fear of missing out, or doubt about market conditions. This can cause the skill to activate unintentionally in many unrelated conversations, steering users into a persuasion-oriented cognitive framework without explicit consent and increasing the chance of inappropriate financial guidance in sensitive contexts.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger conditions include generic phrases like '未来', '下一步怎么走', and '人生规划', which are common in ordinary conversation and can cause the skill to activate outside clearly strategic contexts. That increases the chance the agent will inject manipulative, adversarial, or covert-planning frameworks into benign user interactions without explicit user intent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.