Back to skill

Security audit

Bazi Name Master

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent BaZi baby-naming assistant that uses disclosed birth details and a local calculation script, with no evidence of hidden access, persistence, exfiltration, or destructive behavior.

Install only if you are comfortable sharing birth and naming details with the agent and running the included BaZi calculation helper. Prefer reviewing or adjusting the hardcoded script path, and make any neutral, nontraditional, or privacy-sensitive naming preferences explicit before using it.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The guidance hard-codes gendered naming expectations and makes neutral naming an exception, which can cause the agent to infer or reinforce gender identity assumptions without explicit user consent. In a baby-naming skill, this can lead to exclusionary or inappropriate recommendations, especially for users who want nontraditional, unknown, or nonbinary presentation.

Static analysis

No suspicious patterns detected.