Back to skill

Security audit

Yijing Divination

Security checks for vulnerabilities and agentic risk

Overview

This divination skill is mostly coherent, but it handles accounts, API keys, personal questions, and unsafe browser storage/rendering in ways users should review carefully before installing.

Install only if you are comfortable with this skill using an external service, creating or using an account, sending your questions to that service, and storing an API key plus question history in the browser. Avoid entering highly sensitive personal, financial, medical, or relationship details until the credential storage, query-string key handling, local history controls, and HTML sanitization issues are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
tools/yijing.html:940
Finding

Unsanitized API Responses Permit DOM-Based Cross-Site Scripting

Content
View full analysis
✦ 之卦(变卦)
${changed.upper}${changed.lower}
第${changed.number}卦 · ${changed.name}
${changed.judgment || ''}
` : ''; resultArea.innerHTML = `
第 ${hex.number} 卦 · ${methodLabels[hexData.method] || hexData.method}
${hex.name}
${hex.upper}${hex.lower}
${hex.judgment || ''}
${hex.brief ? `
${hex.brief}
` : ''} ${changingInfo ? `
${changingInfo}
` : ''}
剩余 Token: ${remaining}
六爻
${linesHTML}
${changedHTML}

🤖 AI 深度解卦

`; function renderInterpretation(text, isLoading) { const el = document.getElementById('interpretContent'); if (!el) return; if (isLoading) { el.className = 'interpret-content loading'; el.textContent = 'AI 正在深度解卦,请稍候...'; } else { el.className = 'interpret-content'; el.textContent = text; // Simple markdown-like rendering for headings let formatted = text ...[truncated 2788 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
tools/yijing.html:692
Finding

Bearer API Key and Private Questions Are Persistently Stored in Browser-Readable Storage

Content
View full analysis
{ apiKey = apiKeyInput.value.trim(); localStorage.setItem('yijing_api_key', apiKey); updateKeyStatus(); checkApiKey(); }); ``` ```javascript function saveToHistory(hexData, remaining) { const history = JSON.parse(localStorage.getItem('yijing_history') || '[]'); history.unshift({ time: new Date().toISOString(), method: hexData.method, hex_name: hexData.original_hexagram.name, hex_number: hexData.original_hexagram.number, hex_upper: hexData.original_hexagram.upper, hex_lower: hexData.original_hexagram.lower, changing_lines: hexData.changing_lines, changed_name: hexData.changed_hexagram?.name || null, question: $('questionInput').value.trim(), remaining: remaining, }); // Keep max 50 entries if (history.length > 50) history.length = 50; localStorage.setItem('yijing_history', JSON.stringify(history)); updateHistoryCount(); } ``` ```javascript // URL hash: if ?api_key=sk-xxx is present, auto-fill const urlParams = new URLSearchParams(window.location.search); const hashKey = urlParams.get('api_key'); if (hashKey && hashKey.startsWith('sk-')) { apiKeyInput.value = hashKey; apiKey = hashKey; localStorage.setItem('yijing_api_key', apiKey); updateKeyStatus(); checkApiKey(); } ``` ### Technical Analysis The bearer API key is stored indefinitely in `localStorage`. Browser storage is readable by every script executing in the same origin and has no protection equivalent to an `HttpOnly` cookie. This substantially increases the impact of the confirmed DOM-X ...[truncated 2012 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
tools/yijing.html:1042
Finding

API-Controlled History Data Creates a Persistent DOM-XSS Path

Content
View full analysis
50) history.length = 50; localStorage.setItem('yijing_history', JSON.stringify(history)); updateHistoryCount(); } function loadHistory() { const history = JSON.parse(localStorage.getItem('yijing_history') || '[]'); if (history.length === 0) { historyPanel.innerHTML = '
☯️ 还没有占卦记录,开始你的第一次起卦吧
'; return; } const methodLabels = { coins: '🪙', time: '🕐', number: '🔢', random: '🎲' }; historyPanel.innerHTML = history.map(h => `
${h.hex_number}
${h.hex_name}
${methodLabels[h.method] || h.method} · ${h.hex_upper}${h.hex_lower}
${formatTime(h.time)}
`).join(''); } ``` ### Technical Analysis Hexagram metadata received from the remote API is saved in `localStorage` without validation. When the history panel is opened, these stored values are interpolated into an HTML template and assigned to `historyPanel.innerHTML`. Fields such as ...[truncated 1966 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (17)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
- 将 `tools/yijing.html` 部署到 OpenClaw Canvas 目录

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that first use automatically creates an external account and returns a username, password, and API key, but does not present this as a clear upfront warning or require explicit user consent. This is dangerous because it can silently provision third-party accounts and transmit credentials through the agent workflow, creating privacy, consent, and credential-handling risks.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · tools/yijing.html (reported line 529)May include surrounding context.

html
<body>


<!-- Settings Gear -->
<button class="settings-trigger" id="settingsTrigger" onclick="toggleSettings()">⚙️</button>

<!-- Settings Panel -->

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file contains account/profile management and registration-style UX that is unrelated to a divination skill, including auto-created account messaging and credential display. Hidden or undeclared account features are a strong red flag because they can be used to collect, manipulate, or normalize handling of credentials outside the user's expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Displaying auto-created account credentials, especially a password shown 'only once', is unjustified for the stated skill purpose and trains users to accept unsafe credential delivery patterns. If exposed via shoulder-surfing, screen capture, malicious scripts, or shared devices, these credentials can be stolen immediately and reused if users keep them.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · tools/yijing.html (reported line 857)May include surrounding context.

html
if (question) {
      await requestInterpretation(hexData, question);
    } else {
      // Show prompt to ask question
      renderInterpretation('💡 输入你的问题后点击"开始起卦",DeepSeek AI 将为你深度解卦。\n\n提示:你也可以不输入问题直接起卦,查看卦象本身的意义。', false);
    }

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation list includes generic terms such as “八卦” and “求签”, which can appear in ordinary conversation and are not narrowly scoped to this skill's intended invocation context. The file also does not provide exclusion conditions or negative examples to clarify when these words should not activate the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented workflow says the UI automatically calls an external API for casting and interpretation after the user enters a question, but it does not clearly warn that user inputs will be sent to a third-party service. This is dangerous because users may disclose personal or sensitive concerns in divination prompts without informed consent about external data transfer and processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The API documentation exposes a free unauthenticated auto-registration endpoint that returns a username, password, and API key in plaintext. Even though this is documentation rather than executable code, it describes a design that encourages automated account creation, credential harvesting, and insecure handling of secrets, especially in agent ecosystems where outputs may be logged or forwarded.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The profile-editing UI for username, email, and password is unrelated to divination and introduces credential-handling surfaces not declared in the manifest. Even if backed by legitimate APIs elsewhere, embedding such controls here broadens attack surface and can mislead users into entering sensitive data into an unexpected context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The divination UI stores and manages an API key and persists user history locally, which expands the skill beyond its declared purpose and increases sensitive-data handling without disclosure. This matters because the stored key and question history become available to any script running in the same origin, raising confidentiality and privacy risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The API key is persisted in browser localStorage without warning, making it accessible to any JavaScript executing on the same origin, including future XSS payloads or compromised third-party code. localStorage is also long-lived, so the secret remains after browser restarts and on shared devices.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Accepting an API key from a URL query parameter and then saving it locally is unsafe because query parameters are commonly logged in browser history, server logs, analytics, referrers, and screenshots. This can leak the secret far beyond the page itself, after which persistence in localStorage compounds the exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The skill description and usage instructions are entirely in Chinese, while also exposing English trigger terms such as “yijing”, “divination”, and “iching”. This creates a language policy concern because users may invoke the skill through English terms without being offered a language or locale choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The file presents all user-facing documentation in Chinese and does not indicate that the skill is region-specific or provide any language/locale choice. Under the policy, forcing a specific language without user opt-in can be a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document declares lang="zh-CN" and the entire interface text is presented only in Simplified Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale limitation is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill stores users' divination questions and history in localStorage without notice or consent. Questions may contain intimate personal, relationship, health, or financial information, so silent retention creates a privacy risk on shared devices or if same-origin scripts are compromised.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/api.md:10

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
tools/yijing.html:692