Back to skill

Security audit

qiyue-bazi-drawer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed astrology chart lookup that sends user-provided birth details to QiyueAstro's public API and has no executable installer or persistence.

Install only if you are comfortable sending birth date, birth time, gender, and any optional question text to qiyueastro.com. Avoid putting sensitive personal details in the optional question, and treat the output as entertainment or self-exploration rather than advice.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README explicitly states that users provide birth date, birth hour, and gender, and that this data is sent to a public third-party API, but it does not warn users about the privacy implications or data handling risks. Birth data is sensitive personal information in many contexts, and transmitting it off-platform without clear disclosure, consent language, or retention details can expose users to privacy harm and compliance issues.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill sends sensitive personal data—birth date, birth time, gender, and an optional free-form question—to a third-party API without clearly warning the user before transmission. Birth data is highly sensitive in many contexts, and the optional question may contain additional personal details, so silent exfiltration to an external service creates a meaningful privacy and consent risk.

Static analysis

No suspicious patterns detected.