Back to skill

Security audit

千门八将108局·

Security checks for vulnerabilities and agentic risk

Overview

This text-only skill openly teaches and routes users into hidden influence and manipulation workflows, so it needs Review before installation.

Review this skill carefully before installing. It has no apparent malware-like install behavior, but it can cause an assistant to produce covert influence, manipulation, and social-engineering strategy. Use only in tightly bounded defensive, historical, or critical-analysis contexts with explicit rules against applying tactics to real people.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
This file is not neutral historical commentary; it is a structured catalog of manipulation schemes with concise operational descriptions for exploiting trust, fear, guilt, emotion, and information asymmetry. In the context of an AI skill marketed as a strategy engine, this materially enables social-engineering abuse and covert coercion rather than safe study or defense.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The document gives actionable playbooks for deception and coercion, including trust-building pretexts, emotional leverage, rumor-spreading, dependency creation, and staged exploitation. These patterns can be directly repurposed for fraud, abuse, psychological manipulation, and targeted social engineering against users or third parties.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill presents itself as broadly applicable strategic guidance and can be invoked from ordinary user phrasing, which increases the chance of unintended activation in benign conversations. In a skill that discusses manipulation, deception, and influence tactics, overly broad triggering materially raises misuse risk because harmful workflows may activate without clear user intent or safety gating.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The mode-selection rules rely on vague natural-language signals like emotional tone or generic goals, making routing unpredictable and easy to trigger accidentally. Because one branch leads to '战略设计' that includes concealment and '收网,' ambiguous dispatch can steer ordinary planning requests into covert-influence guidance without sufficient verification.

Missing User Warnings

High
Confidence
97% confidence
Finding
The file repeatedly describes harmful deceptive tactics without any warning, ethical framing, or restriction on misuse, which normalizes abuse and lowers barriers to operationalizing it. Absence of safeguards is especially dangerous because the content is organized for easy reference and can be surfaced by an agent as practical guidance.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This content systematically explains manipulative and deceptive tactics, including information asymmetry, incentive distortion, identity construction, and relationship isolation, while presenting them as an operational framework without meaningful ethical guardrails or misuse warnings. In an agent skill context, this can normalize or enable social engineering, coercive persuasion, and exploitative decision-making, especially because the material is framed as a reusable strategic model rather than purely historical or critical analysis.

Ssd 4

High
Confidence
98% confidence
Finding
This section operationalizes a step-by-step strategy for influence campaigns, including hidden intent ('藏局'), covert shaping ('隐局'), and a terminal '收网' phase. In context, this is not abstract theory: it is an executable workflow that can help users plan deception, manipulation, or social engineering in a structured and repeatable way.

Ssd 4

High
Confidence
98% confidence
Finding
The core framework explicitly normalizes concealment and infiltration as standard phases of strategy, framing covert manipulation as routine rather than exceptional. This context makes the rest of the skill more dangerous because it provides a conceptual foundation for abuse across modes, including analysis, defense, and especially strategic design.

Ssd 4

High
Confidence
99% confidence
Finding
The document is a systematic taxonomy of deceptive operations, explicitly framed around attack surfaces such as belief systems, identity, scarcity, relationships, and cognitive bias. That structure makes it more dangerous than incidental prose because it supports selection, adaptation, and repeated use of manipulation techniques across scenarios.

Static analysis

No suspicious patterns detected.