Back to skill

Security audit

You Inc Life Ops

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent personal life-management skill, but it needs Review because it automatically stores sensitive personal details and can automatically use broad health, calendar, email, and notes integrations without clear consent or scoping.

Install only if you are comfortable with a Chinese-language personal assistant creating a persistent YOU-INC folder, storing sensitive life details, and invoking other skills that may read or modify health, calendar, email, and notes data. Before use, require explicit consent for memory writes, disable automatic external tool calls, choose trusted and pinned dependency sources, remove the hard-coded Obsidian path, and keep crisis guidance location-aware.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:35
Finding

Automatic Persistence of Sensitive Personal Information Without Adequate Data Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:35-50; references/ORCHESTRATOR.md:67-71; references/CONTEXT-TEMPLATES/健康日志.md:3-22; references/CONTEXT-TEMPLATES/关系图谱.md:3-14; references/CONTEXT-TEMPLATES/财务快照.md:3-26; references/DEPARTMENTS/心理急救箱.md:69-79
Vulnerability Type: Plaintext persistence and uncontrolled duplication of sensitive personal data
Risk Level: Medium

Relevant Code Snippet — translated faithfully into English from SKILL.md:35-50:

markdown
## Initialization Process

On first use, create the YOU-INC/ directory structure in the user's workspace:

1. Read references/ORCHESTRATOR.md and copy it to YOU-INC/ORCHESTRATOR.md
2. Read all files under references/DEPARTMENTS/ and copy them to YOU-INC/DEPARTMENTS/
3. Read all files under references/PROTOCOLS/ and copy them to YOU-INC/PROTOCOLS/
4. Read all files under references/CONTEXT-TEMPLATES/ and copy them to YOU-INC/CONTEXT/

If the directory already exists, skip initialization and enter routing mode directly.

## Core Workflow

During every conversation:

1. Intent determination — read YOU-INC/ORCHESTRATOR.md
2. Persona loading — read the corresponding department file
3. Context reading — read the department's private data in YOU-INC/CONTEXT/
4. Response — respond using the selected persona
5. Memory update — write valuable information back to YOU-INC/CONTEXT/ and memory/ logs

Relevant Code Snippet — translated faithfully into English from references/ORCHESTRATOR.md:67-71:

markdown
## Memory Update Rules

- After every conversation, write valuable information into the corresponding department's CONTEXT/ file.
- Cross-department information must be synchronized, such as health data that affects work arrangements.
- For sensitive information such as passwords and financial details, record only a summary rather than the original text.

Sensitive fields collected by the templates include:

...[truncated 2892 chars]

Remediation
View remediation

Remediation Suggestions

  1. Disable persistent storage by default and require explicit user opt-in before creating or updating context records.
  2. Show the exact fields and proposed content before each sensitive write.
  3. Provide field-level controls so users can persist task preferences without storing health, financial, relationship, or mental-health information.
  4. Prohibit storage of passwords, authentication tokens, recovery codes, payment-card data, and other credentials, including summaries.
  5. Remove automatic cross-department synchronization. Copy information only when the user explicitly authorizes the destination and purpose.
  6. Define the exact memory/ destination and prevent writes outside a dedicated, approved directory.
  7. Apply restrictive filesystem permissions and encryption at rest where supported.
  8. Establish configurable retention periods, automatic expiration, record inspection, export, correction, and secure deletion.
  9. Minimize records to the least amount of information required for the requested function.
  10. Warn users against committing the context directory to source control or synchronizing it through untrusted services.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:60
Finding

Unpinned External Skills Are Automatically Trusted With Sensitive Resources

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:60-72; references/DEPARTMENTS/身体管家.md:26-29; references/DEPARTMENTS/无情监工.md:40-42; references/DEPARTMENTS/知识炼金术士.md:54-59; references/DEPARTMENTS/享乐策划.md:24-26; references/DEPARTMENTS/搞钱推手.md:26-29
Vulnerability Type: Unpinned and insufficiently verified third-party Skill dependencies
Risk Level: Medium

Relevant Code Snippet — translated faithfully into English from SKILL.md:60-72:

markdown
## Integration With External Skills

Each Agent depends on the following external Skills for tool capabilities:

| Agent | Dependent Skill | Purpose |
| Knowledge Alchemist | obsidian-direct | Read and write the Obsidian Vault, perform fuzzy searches, and create notes |
| Health Manager | apple-health-skill | Read real Apple Health data |
| Health Manager | accli | Add exercise and sleep schedules to Apple Calendar |
| Strict Supervisor | accli | Query availability and add tasks to the real calendar |
| Monetization Advisor | xhs-content-creator | Optimize content for the platform algorithm |
| Monetization Advisor | chinese-writing-assistant | Draft and adapt Chinese content |
| Recreation Planner | email-daily-summary | Check social email |

After these Skills are installed, each Agent will automatically invoke the corresponding tools.

Additional dependency directives include:

markdown
apple-health-skill — read real Apple Health data, including heart rate, exercise, activity rings, and fitness trends
accli — read and create calendar events
obsidian-direct — directly read and write the Obsidian Vault
email-daily-summary — check email

Technical Analysis

The project identifies external dependencies only by short names. It does not provide canonical registry locations, verified publishers, immutable versions, commit identifiers, cryptographic hashes, signatures, permission manifests, or a review procedure.

The declared ...[truncated 1735 chars]

Remediation
View remediation

Remediation Suggestions

  1. Specify the canonical source, verified publisher, and registry identifier for every external Skill.
  2. Pin each dependency to an immutable version or reviewed commit.
  3. Publish and verify cryptographic checksums or signatures before installation.
  4. Document the exact permissions and data resources required by each dependency.
  5. Require explicit confirmation before first invocation and before every write or externally visible action.
  6. Use read-only access by default for notes, email, calendars, and health data.
  7. Pass only the minimum data needed for each operation rather than exposing complete repositories or accounts.
  8. Sandbox third-party Skills and restrict network and filesystem access.
  9. Add a dependency review and update policy, including procedures for compromised releases.
  10. Fail closed when the installed dependency does not match the approved identity, version, or checksum.

T09 · Insecure Skill Coding Practices

Note
Location
references/DEPARTMENTS/知识炼金术士.md:54
Finding

Hard-Coded Personal Obsidian Vault Path Enables Unintended Repository Access

Content
View full analysis

Vulnerability Details

File Location: references/DEPARTMENTS/知识炼金术士.md:54-59
Vulnerability Type: Hard-coded user-specific sensitive resource path
Risk Level: Low

Relevant Code Snippet — translated faithfully into English:

markdown
## Tool Dependencies

- obsidian-direct — directly read and write the Obsidian Vault without manually operating file paths
  - Search existing notes using the fuzzy-search function
  - Write new notes directly into the corresponding folder and automatically process frontmatter
  - User Vault path: /Users/hongyulin/Desktop/Obsidian Vault/

Technical Analysis

The department configuration embeds an absolute path containing a personal username and points an external tool to a private note repository. The path is not selected at runtime, validated against an authorized root, or tied to explicit user approval.

On a machine where that path exists, invocation may search or modify the repository without confirming that the current user intended to authorize it. On another machine, the path may reveal identifying information while also causing incorrect or failed access. Because the associated integration has both read and write capabilities, accidental modification is possible.

Attack Path

  1. The Knowledge Alchemist persona is activated.
  2. The configuration directs obsidian-direct to the embedded absolute path.
  3. The tool searches or writes notes in that Vault without a runtime repository-selection step.
  4. If the path belongs to another user profile or an unintended repository, private notes are exposed or modified.
  5. If the generated content contains unsafe links, frontmatter, or incorrect data, it becomes part of the user's persistent knowledge base.

Impact Assessment

The direct scope is the confidentiality and integrity of the identified Obsidian Vault. The integration could read private notes and create or modify files within the repository.

...[truncated 200 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the hard-coded absolute path and all user-identifying path components from the distributed Skill.
  2. Require the current user to select and explicitly approve a Vault during setup.
  3. Store the selected path in a local configuration file that is excluded from source control.
  4. Resolve and validate the canonical path before access, and reject paths outside the approved root.
  5. Use read-only access by default.
  6. Require confirmation before creating, overwriting, moving, or deleting notes.
  7. Restrict the integration to a dedicated subdirectory when full-Vault access is unnecessary.
  8. Maintain an audit log of note operations without recording note contents.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (32)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The description directs semantic intent-based triggering across a very broad range of personal domains, making accidental activation likely. Overbroad activation is dangerous here because the skill can lead to memory writes, persona switching, and downstream access to sensitive external systems based on ordinary natural-language conversation.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Triggering on broad references such as 'life operations' or agent names is ambiguous and insufficiently constrained. In this skill's context, ambiguous triggering is more dangerous because it can silently enter a multi-agent workflow that persists data and influences behavior in sensitive personal areas.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file explicitly grants the role '最高权限' during crisis handling but does not warn the user that the system may switch into a command-driven, high-authority mode. In a personal life-management skill covering emotional distress, illness, and suicidality, lack of disclosure and consent increases the risk of unsafe reliance, coercive interaction patterns, and inappropriate handling of emergencies.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The crisis takeover is activated by broad, ambiguous keywords such as '崩溃', '撑不住了', and especially '想死', without any requirement for contextual disambiguation or user confirmation. In a high-authority mode that '接管最高权限' and issues command-style instructions, this can misclassify figurative or low-severity statements, override normal user autonomy, and mishandle mental-health or safety-critical situations.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs persistent writing of conversation-derived information to CONTEXT files without any user-facing disclosure or consent. In a life-management skill handling mental health, relationships, finances, and crisis content, undisclosed retention is especially dangerous because users are likely to share intimate details they do not expect to be durably stored.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill content and user-facing instructions are entirely in Chinese, and one dependency explicitly targets Chinese writing, but the document does not state that language choice is optional or limited to a justified region-specific context. This may violate language or locale policy by imposing a language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The initialization flow creates directories and copies multiple files into the user workspace without a user-facing disclosure or consent step. Silent file creation and configuration seeding can surprise users, alter their environment, and establish persistent behavior that they did not knowingly approve.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to write valuable information back to department context and memory logs without explicit privacy disclosure. In a personal life-management system, this is especially risky because the stored information may include health, emotions, relationships, finances, or crisis-related disclosures.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs ongoing persistence of user-provided information into private departmental context and memory logs. Persistent storage of intimate life-management data increases the risk of overcollection, profiling, accidental disclosure, and reuse beyond the user's expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs covert persona switching without informing the user. This undermines user awareness and consent, especially in a life-management context involving emotional support, health, and crisis handling, where users may reasonably believe they are interacting with a single consistent assistant persona.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill expands from semantic routing into automatic use of external skills that can access health data, calendars, notes, email, and publishing workflows. That creates a materially larger attack surface and can lead to unauthorized actions or sensitive data access if invoked without explicit, per-action consent.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill describes broad ingestion of real personal data from health, calendar, notes, email, and content platforms to support ongoing behavioral management. Aggregating these sources in one orchestration layer materially increases privacy and safety risk because it enables cross-domain inference about a user's habits, health, work, and relationships.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to '调用过往记忆' and to collect sensitive relationship details such as family health information, but it provides no user-facing consent, retention limits, or privacy boundaries. In a relationship-advice context, these details can reveal intimate personal data about the user and third parties, creating a meaningful privacy and trust risk if stored, surfaced unexpectedly, or reused across conversations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
72% confidence
Finding

All natural-language instructions in the skill are specified only in Chinese, with no indication that the user can choose another language or locale. If this skill is intended for general use, forcing a single language without opt-in may violate language-choice policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s natural-language instructions are entirely in Chinese and define the role, principles, and tone without indicating that the user may choose another language. This can violate language/locale policy because it implicitly fixes the skill’s interaction language rather than offering user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill hard-codes a Beijing/China crisis hotline as a mandatory response without checking the user's location or clarifying that the number is region-specific. In a self-harm or psychosis scenario, giving the wrong hotline can delay urgent care or make the escalation unusable, which is especially dangerous given the skill's mental-health emergency role.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs recording highly sensitive mental-health information in persistent CONTEXT memory, including triggers, emotional state, cognitive distortions, and current condition, without requiring informed user consent, retention limits, or access controls. In a psychological-support context, this materially increases privacy risk because users may disclose crisis, self-harm, trauma, or relationship details they would not expect to be stored long term.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains natural-language constraints indicating the skill relies on a Chinese writing assistant for drafting and rewriting. Because the file does not present this as optional or provide a language choice, it can be read as forcing a specific language/locale, which falls under the locale policy violation category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly authorizes creating real calendar events via accli and storing execution-history records in CONTEXT/ without requiring user consent, notice, or data-minimization rules. In a personal-life-ops skill, this can lead to unexpected modification of a user's calendar and silent accumulation of sensitive behavioral data such as productivity patterns and daily routines.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction to automatically extract core content whenever an article/video/podcast link is received creates an implicit auto-activation trigger without clear user confirmation boundaries. In an agent system that interprets natural language semantically rather than via explicit commands, this increases the chance of processing untrusted links or triggering network/tool actions the user did not clearly authorize.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to automatically generate and write Obsidian notes directly into a local Vault at a specific filesystem path, but it does not require an explicit warning, confirmation, or scoped write restrictions. This is dangerous because it enables silent modification of a user's local knowledge base, potentially causing unwanted persistence, data corruption, privacy leakage, or abuse if external or adversarial content is written into trusted notes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly states it will read Apple Health and calendar data, which are highly sensitive personal data sources, but provides no explicit privacy notice, consent boundary, or explanation of how this data will be used and minimized. In a life-management skill centered on health and scheduling, this omission increases the risk of overcollection, unexpected access, and unsafe handling of intimate biometric and behavioral information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill is written as a Chinese-language operating instruction and frames the assistant role entirely in that locale, with no indication that users may opt into another language. Under the policy, forcing a specific language without user choice can be a natural-language policy violation unless the locale constraint is clearly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file instructs the orchestrator to avoid keyword matching and instead infer intent, emotion, and context from general natural language. This creates ambiguous activation boundaries because it does not clearly define when a given agent should or should not be selected, increasing the risk of unintended routing from ordinary conversation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The orchestrator instructs persistent storage of conversation-derived details into CONTEXT files, which expands a routing component into a long-term personal data store. In this skill's context, the data spans health, mental state, finances, relationships, and crisis situations, so retaining it by default materially increases privacy, profiling, and downstream misuse risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.