ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      wasinc

      Safety Report

      真实的人类

      @wasinc

      真实的人类 - 帮助AI识别、分析和建模人类个体。当用户提到"人类建模"、"用户画像"、"人格分析"、"了解一个人"、"分析行为模式"、"真实的人类"时使用。

      29Downloads
      0Installs
      1Stars
      1Versions

      Security Analysis

      medium confidence
      Clean0.08 risk

      The skill is internally consistent with its stated purpose (creating, updating, and using per-user models), but it instructs the agent to store potentially sensitive user data in workspace files and references helper functions without providing implementation—so confirm storage protections and consent flows before use.

      Mar 11, 20265 files2 concerns
      Purpose & Capabilityok

      Name, description, and the files (SKILL.md + two reference docs) all describe human/user modeling and personalization. The required resources (none) and the behaviors (create/read/update user model files) align with the declared purpose.

      Instruction Scopenote

      Runtime instructions explicitly tell the agent to create/read/update files under workspace/human-models/ and to integrate with existing memory files (MEMORY.md, memory/YYYY-MM-DD.md, USER.md). That is coherent for a modeling skill, but it means the agent will be instructed to persist user data. The SKILL.md also lists '内置函数' (analyzeEmotion, extractTopics, etc.) that are not implemented in the package—this assumes platform-provided helpers or other code which is not present in the skill bundle.

      Install Mechanismok

      Instruction-only skill with no install spec, no downloads, and no added binaries — low footprint and nothing written to disk by an installer. All behavior comes from textual runtime instructions.

      Credentialsnote

      The skill requests no environment variables or external credentials (proportionate). However, it prescribes storing potentially sensitive categories of information (health, finances, family issues) and creating '-private' files that it says should be 'encrypted/authorized' without giving implementation details—this creates an unaddressed need for secure storage and access control.

      Persistence & Privilegeok

      always is false and the skill does not request elevated runtime privileges or to modify other skills. The skill's normal autonomous invocation capability is the platform default. Persistent storage behavior (writing user-model files) is part of its function but is limited to the workspace paths it documents.

      Guidance

      This skill appears to do what it says: build and maintain per-user models by writing files in the agent workspace. Before installing, confirm the platform's storage and access controls: who can read workspace/human-models/, are '-private' files actually encrypted at rest and access-restricted, and where are backups stored? Verify the platform provides (or you will supply) the helper functions the SKILL.md assumes (analyzeEmotion, extractTopics, etc.) or that the agent will not fail when they are missing. Ensure explicit user consent and retention/deletion policies for sensitive categories (health, finance, psychological data), and avoid recording extremely sensitive items unless secure mechanisms are in place. If you cannot verify secure storage and consent flows, treat the skill as privacy-sensitive and restrict its use.

      Latest Release

      v1.0.0

      初始发布 - 帮助AI识别和建模人类个体

      More by @wasinc

      Beijing Tech Finance

      4 stars

      self-improving-agent

      @pskoett · 1,456 stars

      Gog

      @steipete · 672 stars

      Tavily Web Search

      @arun-8687 · 620 stars

      Find Skills

      @JimLiuxinghai · 529 stars

      Proactive Agent

      @halthelobster · 426 stars

      Published by @wasinc on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]