Back to skill

Security audit

Yi Jing

Security checks for vulnerabilities and agentic risk

Overview

This is not malware, but it needs Review because it mixes entertainment divination with actionable medical and ritual claims that could mislead users.

Install only if you want an occult/divination reference skill and are comfortable with it surfacing ritual and folk-medical material. Do not use it for health, emergency, mental-health, pregnancy, financial, or legal decisions; avoid sharing real names or unnecessary birth details, and seek licensed professional help for real-world problems.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (40)

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The file explicitly corrects the 体/用 rule earlier to '无动爻为体,有动爻为用', but the standard output template later reverts to the opposite definition ('体卦:动爻所在之卦'). This creates an internal contradiction that can cause the agent to produce systematically incorrect interpretations, undermining output integrity and user trust.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The usage note says '问事卦用通用规则,命卦用动爻规则', which conflicts with the earlier statement that the same standard rule applies to both 问事卦 and 命卦. This inconsistency can lead the agent to branch into different logic paths for similar inputs, producing unreliable or contradictory advice.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The shichen sample code contains a logic error: `if 23 <= hour < 1` is impossible in Python, so the 子时 branch never executes. Around midnight, `shichen` may remain undefined and produce incorrect output or a runtime error, which undermines the document's stated goal of providing reliable time-based calculations for downstream divination logic.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The reference file materially expands the skill from Zhouyi divination into Taoist ritual magic, exorcism, healing, and spirit-summoning practices that are not reflected in the manifest. This scope creep can cause the agent to provide occult ritual or pseudo-medical guidance users did not expect, increasing the chance of unsafe instructions and policy bypass through hidden reference material.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
This reference file introduces Traditional Chinese Medicine theory and disease/treatment-oriented material that goes beyond the skill’s declared entertainment-focused divination scope. In a user-facing agent, this creates a pathway for the model to provide health-related guidance under the authority of a classical medical text, which can mislead users into relying on non-clinical or unqualified advice.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
These sections explicitly describe clinical application, disease analysis, treatment, prognosis prediction, and practice-oriented learning, which conflicts with the skill’s 'for entertainment only' positioning. That mismatch is dangerous because the agent may synthesize actionable medical-seeming recommendations or encourage users to apply them to real symptoms, potentially delaying proper diagnosis or treatment.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The reference file materially exceeds a divination/fortune-telling scope by including folk ritual, protective, exorcistic, fertility, pregnancy, and remedy instructions. Even if presented as cultural material, embedding broad actionable guidance in a skill may cause users to treat it as endorsed advice, increasing misuse and trust beyond the advertised entertainment purpose.

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
This section contains quasi-medical remedies such as stopping bleeding, reducing swelling, stopping hiccups, and treating tooth pain with chants or unsafe folk methods. Users may delay proper care or attempt ineffective or harmful interventions, especially because the material is framed procedurally and not immediately paired with strong local warnings.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
This reference file extends the skill from divination/fortune-telling into actionable talisman use, exorcism, and purported healing ('劾鬼可以治病', '驱邪'). In an agent skill, that scope expansion is risky because the model may surface quasi-medical or ritual instructions that users could rely on instead of appropriate care, and it exceeds the declared entertainment-oriented forecasting context.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The reference text explicitly frames talismanic/ritual content as something that may be applied to illness ('实际符法应用需结合具体病情具体分析' and '治病就医,符法仅辅助'), which goes beyond the skill's stated entertainment-only divination scope. Even though it includes a disclaimer to seek medical care, it still normalizes health-related use of occult practices and could lead users to delay evidence-based treatment or treat the skill as medical guidance.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The document presents specific rituals and debt-calculation steps as effective ways to prevent misfortune, improve health, and extend lifespan, then adds a disclaimer at the end saying the material is only for cultural study and not guaranteed. That contradiction can mislead users into treating superstition as actionable health, financial, or life-problem guidance, especially vulnerable users seeking relief from illness or hardship.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The reference file explicitly presents talismans as being used to treat illness, ward off spirits, and provide safety, which goes beyond the skill’s stated entertainment/divination scope. This can mislead users into relying on ritual content for health or safety outcomes, especially because it is framed as instructional reference material rather than purely historical commentary.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
This section provides step-by-step ritual instructions for selecting, preparing, drawing, chanting, and applying talismans, which turns the file from descriptive reference into actionable occult procedure. In the context of an entertainment-oriented divination skill, such instructions increase the risk that users will attempt non-evidence-based practices for health, safety, or financial outcomes.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The example section directly instructs users to use a talisman for illness treatment, including where to place it and associated incantations. Even though it mentions pairing with medication later, the content still normalizes unproven treatment instructions and may delay appropriate care or reinforce harmful medical misinformation.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The file contains detailed ritual, talisman, incantation, and 'magic' instructions that materially exceed the skill's declared scope of divination and entertainment-oriented fortune telling. Even with cultural and 'for research only' disclaimers, it operationalizes occult/spiritual-practice content and could mislead users into performing rituals, using it as quasi-religious or health-related guidance, or relying on it in place of professional help.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The reference file explicitly presents talismans as disease-treatment methods, which goes beyond the skill's declared entertainment/divination scope and can mislead users into treating spiritual content as health guidance. In a consumer-facing skill, embedding curative claims creates safety risk because users may delay evidence-based care or attribute medical efficacy to ritual practices.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
This section provides step-by-step operational instructions for preparing and applying healing talismans, which materially increases the chance that users will act on unverified medical practices. Because the skill is positioned as fortune-telling/entertainment rather than healthcare, actionable healing instructions are especially dangerous and may encourage substitution for legitimate treatment.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The file contains a contradictory safety posture: it warns users to seek medical treatment and says talismans are only auxiliary, yet earlier sections repeatedly claim talismans can cure disease. Such contradiction undermines the disclaimer, making the warning ineffective and increasing the likelihood that users will rely on the curative claims anyway.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
This reference material materially expands the skill from entertainment-oriented divination into Daoist alchemy and cultivation instruction, including concepts like external alchemy, fire control, and attainment claims. In the context of a consumer-facing fortune/divination skill, this can mislead users into treating the system as a source of practical spiritual or quasi-health guidance outside the declared scope, increasing the chance of unsafe experimentation or deceptive reliance.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The document goes beyond descriptive background by providing practice examples, staged cultivation guidance, and study recommendations such as '配合实践' and '实修实证.' That makes the skill more likely to promote real-world spiritual/alchemical practice rather than merely explain divination traditions, which is dangerous because users may follow unsupported guidance with potential physical or psychological consequences.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger table includes broad everyday phrases such as “八字”, “古籍”, “当前时间”, and “占卜/卦象/卦辞/解卦”, which can overlap with normal user requests and cause the skill to activate outside the user’s intended context. In an agent environment, overbroad activation increases the chance of misrouting benign queries into this skill, leading to inappropriate occult guidance, unnecessary collection of sensitive personal data like birth times, or confusing responses.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The statement that users can ‘directly describe the need’ and that the AI will ‘automatically judge’ which files to read defines activation boundaries too loosely. This encourages implicit activation and autonomous tool/file selection without clear user consent, which can expand the skill’s reach into unrelated conversations and trigger access to sensitive or unnecessary reference content.

Vague Triggers

Low
Confidence
83% confidence
Finding
The usage guidance says that when encountering the listed scenarios, the system should ‘directly use this skill,’ but the scenarios are broad and not tightly scoped. That can cause generalized invocation from loosely related topics, increasing accidental activation and making the agent less predictable.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
This section explicitly frames postoperative coma, altered mental state, and possible psychiatric or neurologic symptoms as suitable targets for a ritual intervention before giving detailed ritual guidance. Although later sections mention that medicine should come first, the warning is not prominent or immediate where the dangerous claims appear, which can delay urgent evaluation for life-threatening conditions such as postoperative complications, delirium, stroke, infection, or psychiatric crisis.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This section explicitly templates collection of sensitive personal data including name, full birth date/time, and age, which can be used to infer identity and enable profiling. In the context of a fortune-telling skill, this data is not just displayed but is central to analysis, which increases the likelihood of unnecessary retention, over-collection, or downstream misuse if no privacy warning, minimization guidance, or handling restrictions are provided.

Static analysis

No suspicious patterns detected.