Back to skill

Security audit

create-psychological-counselor(创造/蒸馏心理咨询师)

Security checks for vulnerabilities and agentic risk

Overview

The skill is not obviously malicious, but it needs Review because it handles sensitive mental-health materials and can enter counselor-style support too broadly.

Install only if you understand this is not a therapist or medical tool. Do not upload identifiable client, session, supervision, or case records unless you have clear authorization and have redacted them. Review generated counselor files before using or sharing them, require explicit confirmation before support-mode interactions, and delete local counselor/version files when no longer needed.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The skill disclaims professional counseling, but its actual behavior explicitly includes simulating counselor responses, emotional support, and virtual therapist use cases. That mismatch can cause users to rely on it as mental-health guidance despite the disclaimer, especially in distress contexts where users may not distinguish 'support' from counseling.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The generated skill is presented as only for learning and basic support, yet it is designed to engage users reporting depression, anxiety, insomnia, and simulated counseling needs. In practice, this invites quasi-therapeutic interaction while reducing accountability through disclaimers, which is risky for vulnerable users.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases include broad emotional statements such as '我心情不好' and '最近压力有点大', which are common in ordinary conversation and can cause the skill to activate unintentionally. In a mental-health-themed skill, accidental activation is more dangerous because users may disclose sensitive emotional or clinical information without clearly intending to invoke this tool.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The search-style trigger phrases are overly broad and not tightly bound to the skill's specific purpose of creating a digital counselor persona. This can capture general questions about psychotherapy or finding a counselor, leading users into a skill they did not mean to invoke and increasing the chance of confusion, misplaced trust, or inappropriate reliance.

Missing User Warnings

High
Confidence
98% confidence
Finding
The README explicitly encourages importing highly sensitive materials such as counseling records, supervision records, case conceptualizations, and personal interviews, but does not provide concrete privacy, consent, minimization, retention, or deletion guidance. Because these materials can contain health information and third-party confidential disclosures, misuse could expose protected personal data and violate counseling ethics or data-protection obligations.

Vague Triggers

High
Confidence
95% confidence
Finding
These trigger phrases are broad everyday expressions such as feeling stressed, sad, or wanting to talk, so the skill may activate unintentionally in ordinary conversation. Because the skill then enters a mental-health support flow, accidental invocation can expose users to inappropriate counselor simulation and collection of sensitive psychological material.

Vague Triggers

High
Confidence
95% confidence
Finding
The English distress triggers are generic and likely to appear in routine conversation, causing the counselor skill to activate without clear user intent. In a sensitive domain like mental health, accidental activation increases the chance of unsafe support flows and mishandling of crisis-adjacent statements.

Vague Triggers

Medium
Confidence
84% confidence
Finding
These informational queries about counseling and AI are ambiguous and may trigger the full skill even when the user is only asking a general question. That expands the skill's reach into unintended contexts and can lead to unnecessary collection, generation, or guidance in a high-sensitivity domain.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The English question triggers are broad enough that casual discussion about counseling reliability or AI counseling could activate the skill unintentionally. In the mental-health context, such unintended activation is more dangerous because it may steer users into simulated support without informed consent.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger phrases include broad, everyday distress statements such as feeling depressed, stressed, or wanting someone to talk to. In a mental-health skill, this can cause unintended activation during ordinary conversation and route vulnerable users into an automatically selected counselor-simulation or support mode without clear consent or safety triage. The mental-health context makes this more dangerous because ambiguous activation can affect users in distress and create confusion about whether they are receiving informal support, simulated counseling, or something that appears clinically authoritative.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The search/question triggers are broad enough to overlap with ordinary discussion about therapy, counselor reliability, or general information-seeking. This can activate the skill when the user is only asking a general question, creating mode confusion and potentially steering them into counselor-cloning or simulated support flows they did not request. In this domain, even informational queries should not silently transition into mental-health interaction modes.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The document states that one of three usage modes is chosen automatically, but it does not define the decision criteria, boundaries, or disallowed transitions. In a mental-health setting, automatic mode selection can misclassify user intent and move a vulnerable user into simulated counseling or emotional-support behavior without transparency, consent, or adequate safety handling. The included disclaimers reduce some risk, but they do not compensate for unclear activation and routing logic.

Static analysis

No suspicious patterns detected.