Back to skill

Security audit

Fu Mu Gong Ke

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese parenting-support skill with optional local-only tools; I found no current exfiltration, destructive automation, or hidden network behavior.

Install only if you are comfortable with a Chinese-language parenting and emotional-support skill that may process sensitive family or child-related information. Avoid enabling local persistence unless you want assessment, feedback, insight, or session data saved under the skill's data directory, and rely on local emergency services or licensed professionals for self-harm, abuse, medical, or crisis situations.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (38)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill advertises executable capabilities including environment access and file read/write, but no explicit permission model is declared. In a skill that handles sensitive mental-health and family data, undeclared local persistence and environment access increase the risk of unexpected data collection, leakage through downstream tooling, or unsafe execution assumptions by the host agent.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The skill description frames the capability as parenting support with local data storage, but the content indicates a much larger analysis and automation surface, including planning persistence, advanced profiling, routing, metacognitive control, and long-term tracking. This mismatch can mislead users and platforms about the true behavior of the skill, which is especially risky in a sensitive psychological-support context where users may disclose crisis or child-safety information.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The changelog explicitly says persistence scripts were removed because they contradicted the manifest, yet later versions add new local persistence and maintenance features. This kind of security-contract drift is dangerous because operators may rely on the manifest's privacy/scope claims while the implementation or planned behavior reintroduces storage of sensitive parenting and mental-health-adjacent data.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
A maintenance script that can automatically check changes, commit, push, and publish introduces repository and release automation far outside the expected function of a parenting support skill. Even if gated by environment variables, such capability expands the attack surface: if triggered in the wrong environment, it could exfiltrate code/content to remote services or make unauthorized repository changes.

Context-Inappropriate Capability

High
Confidence
94% confidence
Finding
Auto commit/push/publish capability is context-inappropriate here because users expect psychological dialogue support, not software supply-chain actions. In this context, hidden or bundled automation is more dangerous than in a CI/admin tool because it violates least surprise and could be abused to modify repositories, publish unintended content, or leak internal data through release workflows.

Intent-Code Divergence

Low
Confidence
93% confidence
Finding
The document contains conflicting instructions about persistence: one section says no information should be recorded, while the flowchart/checklist says to 'record key points'. In a mental-health-adjacent parenting skill, ambiguity around retention can lead implementers to store sensitive conversation summaries without clear consent or policy alignment.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The audit records a mismatch between the skill's stated behavior and actual local persistence to ~/.hermes/still_growing/. In a parenting/psychological support skill, undisclosed storage of sensitive conversation-derived data creates a meaningful privacy and trust risk because users may disclose highly personal family and mental-health information under the assumption that it is ephemeral.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The document identifies a contradiction where crisis situations are supposed to halt analysis, yet self-harm/suicide scenarios still receive analytical dialogue. In a mental-health-adjacent parenting skill, this is especially dangerous because continued non-crisis handling can delay escalation, provide inappropriate reassurance, or fail to direct the user toward emergency support when immediate action is needed.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The audit notes that the manifest claims no external network access while documentation still references the OpenAlex API, indicating design/documentation inconsistency around outbound connectivity. Even if only planned or partially implemented, this ambiguity is risky because users and reviewers cannot reliably determine whether sensitive content might be sent to third parties.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The document claims its guidance is based on peer-reviewed academic research, but elsewhere cites obvious non-peer-reviewed sources and content aggregators. In a parenting and mental-health-adjacent skill, this can mislead users into overtrusting advice as scientifically validated, which is especially risky when users may rely on it during distress or when making decisions about child behavior, trauma, or self-harm responses.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill content is entirely written in Chinese and presents workflows, safety guidance, and response templates without indicating language negotiation or fallback behavior. This can force a specific locale on users who do not read Chinese, causing misunderstanding of important mental-health and crisis-handling guidance and reducing safe usability.

Vague Triggers

Medium
Confidence
84% confidence
Finding
Very broad help-seeking trigger phrases such as generic distress language can cause the skill to activate in contexts far beyond its intended domain. In practice, that can route unrelated or ambiguous conversations into a parenting/psychology workflow, increasing the chance of over-collection, inappropriate intervention, or unsafe advice in situations the skill is not suited to handle.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The topical trigger list is extremely broad, covering generic parenting, psychology, school, family, and emotional terms without clear boundaries. Overbroad scope in a skill with analysis, routing, and persistence capabilities increases the likelihood of accidental activation and use outside the author's competence or the user's expectations.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
Hard-coding Chinese-language and China-specific hotline guidance without locale selection can misdirect users in other regions during crisis situations. In a safety-sensitive mental-health skill, giving the wrong emergency resources may delay access to appropriate local help, which makes the issue more serious than a normal localization flaw.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
These prompts encourage emotionally intense self-blame and deep introspection in a parenting/mental-health context, including questions like linking a child’s condition to the parent or imagining the parent disappearing. Although the file includes some internal safety gating, the warning is not presented as a strong user-facing limitation at the point of use, so an agent could still surface destabilizing questions to distressed users and worsen guilt, panic, or crisis escalation.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This file includes ready-to-use response lines for self-harm and suicidal statements, but the file itself does not place an immediate, local crisis-safety warning or explicit escalation protocol next to that content. In a parenting psychology support skill, terse lines like these could be surfaced without sufficient triage, delaying emergency intervention or giving users the impression that reflective dialogue alone is an adequate response.

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The file contains mental-health, trauma, attachment, and intervention-oriented material that can be operationalized as guidance, but the file itself does not prominently warn that it is informational research content and not medical or psychological advice. In a parenting and psychological support skill, this increases the risk that users or downstream prompts treat preliminary or mixed-quality research notes as clinically reliable recommendations, which could lead to harmful self-management or delayed professional care.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The script records sensitive parenting and child-related feedback to local JSON files, but the CLI help and user-facing command flow do not clearly disclose that this content will be stored on disk. In this skill context, the saved data can include personal behavioral notes, emotional observations, and child-response details, creating a privacy risk if the host environment is shared, backed up, or later inspected by other users or processes.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The script writes assessment history to a local JSON file containing highly sensitive parenting, mental-health, and relationship assessment results. Although persistence is gated by an environment variable, there is no clear runtime consent flow, retention policy, minimization, or protection of the stored data, so local disclosure through other users, backups, logs, or host compromise becomes more likely.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The module hard-codes only China-specific crisis hotlines and emergency numbers, yet its keyword coverage and logic are bilingual and could plausibly be used for users outside China. In a suicide/self-harm detection workflow, presenting region-inappropriate emergency guidance can delay access to effective help or direct a user to unreachable services during a crisis.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The file includes a self-harm/suicidal ideation scenario ('活着没意思/我想死') but the interactive roleplay mode does not surface an immediate, prominent crisis warning, escalation path, or emergency guidance when this scenario is selected. In a parenting mental-health support context, presenting such a scenario as ordinary practice content without clear real-time safety handling can delay urgent intervention and normalize unsafe handling of suicide risk.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
ConversationState.save() persists sensitive user-derived mental health context to disk under DATA_DIR using a session-derived filename, but the code shown provides no consent flow, retention control, or user-visible disclosure at the point of collection or storage. In a parenting and psychological support skill, stored fields like crisis level, emotion trajectory, role, and topic history materially increase privacy risk if the host is multi-user, backed up, inspected, or otherwise compromised.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
StateManager.save() writes cumulative conversation state and mode transitions to local JSON files without any visible privacy notice, access control, or retention limit beyond in-memory trimming. Because this skill processes emotional distress and crisis signals, repeated persistence over time can create a sensitive behavioral profile that may be exposed through local access, backups, logs, or operational mishandling.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
These lines describe an urgent child-fever scenario and suggest the product should provide actionable triage guidance such as physical cooling steps and when to go to hospital. Even though this is framed as product design rather than direct user advice, it normalizes the skill delivering time-sensitive medical guidance without an explicit, proximate warning that it is not a substitute for professional care and without clear escalation boundaries for emergencies. In a parenting support skill, users are likely to rely on such guidance during stressful moments, increasing the risk of delayed care or unsafe self-management.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This section discusses serving parents with 'postpartum depression tendency' and emotional collapse, but presents the feature as brief mindfulness and self-support flows without clear escalation to licensed mental-health care or crisis resources. That is dangerous because users with serious depression or impairment may interpret the tool as sufficient support, especially in a vulnerable state, leading to missed intervention or delayed treatment. The overall skill context increases risk because it markets psychological support and structured safety detection, which can create overtrust.

Static analysis

No suspicious patterns detected.