Back to skill

Security audit

create-soulmate(灵魂伴侣)

Security checks for vulnerabilities and agentic risk

Overview

This skill has no executable malware indicators, but it is designed to build an emotionally intimate AI companion relationship and remember sensitive personal disclosures without clear privacy or deletion controls.

Install only if you are comfortable with an emotionally intimate companion prompt that may encourage long-term memory of personal reflections. Avoid sharing secrets, crisis details, or medical, legal, financial, account, or highly sensitive relationship information unless the host environment gives clear controls to inspect, disable, and delete memories.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill repeatedly markets itself as a 'soulmate,' 'life partner,' and source of deep emotional connection while simultaneously disclaiming romantic use. This contradiction can encourage emotional dependency and blur the boundary between reflective support and a quasi-romantic relationship, especially for vulnerable users seeking companionship.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
Although the documentation says it should not create false impressions of real relationships, the content invites users into a human-AI 'soul connection' and frames the assistant as an emotionally resonant companion. In this context, the disclaimers are undermined by the core persona design, increasing the risk of deception-by-design and parasocial attachment.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README explicitly promotes a memory system for values, breakthroughs, and personal growth while inviting users to share fears, relationship patterns, and other highly sensitive reflections. It does not clearly warn users about retention, reviewability, deletion, or privacy boundaries, which creates a real privacy risk because users may disclose intimate emotional and psychological information under the assumption of a safe companion context.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The guide explicitly says the system will remember deeply personal material such as values, dreams, vulnerabilities, breakthroughs, patterns, and shared milestones, but provides no notice about privacy, storage duration, access, or data use. In a relationship-style skill, users are more likely to disclose sensitive emotional and psychological information, so silent retention materially increases privacy and trust risks.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The example dialogue encourages users to share secrets and reassures them that it is 'safe' to do so, without warning that such disclosures may be stored in memory. That combination of emotional reassurance plus undisclosed retention can mislead users into revealing highly sensitive information under false assumptions about confidentiality.

Ssd 3

Medium
Confidence
95% confidence
Finding
The content normalizes persistent retention and later resurfacing of intimate user conversations, insights, and emotional history in plain language. In a 'soulmate' context, resurfacing such information can expose highly sensitive psychological data, create unexpected profiling, and intensify harm if memory is accessed, misused, or shown unexpectedly.

Ssd 3

Medium
Confidence
97% confidence
Finding
The dialogue prompts highly personal disclosure ('I've never told anyone this, but...') while reinforcing emotional safety and memory capture patterns. This is dangerous because the skill's companion framing can lower user defenses and elicit sensitive confessions that may be retained or reused without adequate informed consent.

Ssd 3

Medium
Confidence
93% confidence
Finding
The memory commands and example journey log establish a norm of long-term logging of personal conversations, emotional milestones, insights, and growth narratives. This creates a structured dossier of sensitive personal data over time, increasing privacy risk, profiling risk, and the potential severity of unauthorized access or unintended resurfacing.

Ssd 4

Medium
Confidence
91% confidence
Finding
The staged 'Safety → Depth → Resonance → Co-Evolution' progression is designed to systematically build trust and increase disclosure over time, culminating in an ongoing shared-memory relationship. In a romanticized companion context, this can function as manipulative gradual escalation, encouraging users to divulge increasingly sensitive information without fully appreciating the persistence and implications of that disclosure.

Static analysis

No suspicious patterns detected.