Back to skill

Security audit

赛博命理师

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable fortune-telling skill, but it asks for sensitive birth details and optional face or palm photos while giving health, lifespan, and appearance-based judgments with weak safeguards.

Install only if you intentionally want an entertainment fortune-telling skill and are comfortable sharing sensitive birth details or optional images in chat. Do not treat its health, lifespan, relationship, fertility, wealth, status, or character claims as reliable guidance, and avoid using it for decisions about yourself or other people.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The file expands palm-reading into health-style assessment by mapping palm color and hand temperature to conditions such as blood deficiency, spleen/stomach problems, or serious illness. In a fortune-telling skill, presenting these claims as procedural outputs can mislead users into treating non-medical visual guesses as health guidance, especially because the workflow frames them as standardized diagnostic steps.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The document explicitly instructs the system to infer health conditions from palm appearance, including physiological and disease-like interpretations, without scientific basis or safety guardrails. That creates a risk of false reassurance, unnecessary alarm, or delayed medical care because users may believe the output reflects actual health status.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes broad everyday terms like “星座”“运势”“占卜”, which can match casual conversation and activate the skill without clear user intent. In this skill’s context, unintended activation is more concerning because the workflow then solicits sensitive personal data such as birth details and face/palm photos.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The activation logic explicitly allows vague requests like '帮我算一卦' or '看看我的命' without defining limits or confirmation boundaries. Because the skill proceeds into collection of birth data and potentially biometric images, ambiguous activation can cause over-collection and surprise users who did not intend to share sensitive data.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill requests birth date, birth time, birth location, gender, and optionally face and palm photos, all of which are sensitive personal data, with no upfront privacy notice, consent language, retention policy, or handling limits. In this context, face and palm photos increase risk because they are biometric-like data, and combining them with demographic details raises profiling and privacy exposure concerns.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The health section explicitly produces health assessments and even '寿命预期:长寿' style lifespan output without any disclaimer that the content is non-medical and should not guide diagnosis or treatment. In a fortune-telling skill, users may still act on health or longevity claims, causing delayed care, anxiety, or harmful self-management decisions.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
This file operationalizes physiognomy as a structured decision process that labels people as '贵/贱', '善良/不善', '狠毒阴险', '愚钝短命', and predicts health, wealth, morality, and life outcomes from facial features, without any disclaimer that such claims are unscientific and inappropriate for real-world decisions. In context, this is more dangerous than generic entertainment content because it provides step-by-step scoring and a report template that can be used to legitimize biased profiling or discriminatory judgments about a person's character, capability, or destiny from appearance alone.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill gives factual-sounding interpretations about lifespan, health problems, and major life outcomes from palm lines without warning that palmistry is speculative and not evidence-based. Users may over-trust these statements because they are presented in structured standards and '吉/凶' judgments rather than as entertainment.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The file instructs the model to infer marriage stability, fertility/children, and family outcomes from hand markings without any warning about uncertainty or sensitivity. These are sensitive personal domains, and authoritative presentation can cause emotional harm, reinforce stigma, or influence intimate decisions based on unsupported claims.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The flagged section contains explicit gendered moral prescriptions and derogatory predictions about women, such as framing female virtue in terms of obedience and chastity and associating certain chart features with servility or poverty. In the context of a fortune-telling skill that may present these statements as personalized guidance, this can directly produce discriminatory, demeaning, or harmful outputs to users rather than remaining purely archival reference material.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This content explicitly links physical features and facial characteristics to wealth, status, intelligence, misfortune, and lifespan, presenting these claims as authoritative guidance without any disclaimer that they are non-scientific or entertainment-only. In a user-facing fortune-telling skill, such material can mislead users into making judgments about themselves or others based on physiognomy, reinforcing discriminatory and harmful beliefs.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The quoted section includes explicit gender-normative guidance about women ('女命以柔顺为本,以贞洁为德') without context, framing, or user opt-in. In this skill's fortune-telling context, that content can reinforce discriminatory stereotypes and cause psychological or social harm by presenting biased norms as authoritative guidance.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.