fortune-master-pro

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only fortune-telling guidance skill with expected personal-detail prompts and no executable code, external data flow, or persistence.

Use this as symbolic or entertainment guidance, not professional advice. Share only birth, relationship, and home-layout details you are comfortable putting into chat, and avoid providing exact third-party personal details without consent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This section asks users for birth date, birth time, birthplace, gender, and related profiling inputs that are sensitive personal data in aggregate, but it provides no privacy notice, minimization guidance, retention statement, or warning about sharing third-party data. In a divination skill, these fields may be framed as necessary for service quality, which makes over-collection more likely and increases the chance users disclose identifying information without informed consent.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill requests relationship background and detailed contextual information about two people, which can expose sensitive interpersonal, emotional, and potentially third-party personal data without any warning that this information is sensitive. Because the skill explicitly invites disclosures about relationship state and another person's birth data, it increases the likelihood of collecting non-consensual third-party information and enabling detailed personal profiling.

VirusTotal

53/53 vendors flagged this skill as clean.

View on VirusTotal