Back to skill

Security audit

奇门遁甲

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed paid API connector for BaZi and Qi Men calculations, but users should understand it sends personal birth details and questions to an external service.

Before installing, review the provider's privacy policy and terms, configure only the intended API key, and avoid submitting birth details, sex, or sensitive life questions unless you are comfortable sending them to xiaoqizhisuan.cn. Also note that calls are pay-per-use, with the manifest requiring confirmation and a ¥2 per-session spend cap.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill sends sensitive personal data to a third-party API, including birth date/time, sex, and user questions, but does not present a prominent privacy warning at the point of use. Users may disclose highly sensitive profile and life-information without understanding that it is transmitted off-platform to an external provider, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

1. 初始化连接 | Initialize Connection

bash
curl -X POST https://www.xiaoqizhisuan.cn/mcp \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "x-api-key: ${XIAOQIZHISUAN_API_KEY}" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

1. 初始化连接 | Initialize Connection

bash
curl -X POST https://www.xiaoqizhisuan.cn/mcp \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "x-api-key: ${XIAOQIZHISUAN_API_KEY}" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
76% confidence
Finding

Unlike the initialize and tools/list examples, this documented tool call transmits user-provided personal data such as birth date, birth hour, and sex to a third-party service. In context, the transmission is expected and disclosed at a high level, but it still creates a real privacy exposure because sensitive personal attributes are sent externally without a strong in-band warning or consent flow.

Content

Scanner excerpt · SKILL.md (reported line 219)May include surrounding context.

text
### 3. 调用指定工具 | Call Target Tool
```bash
curl -X POST https://www.xiaoqizhisuan.cn/mcp \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "x-api-key: ${XIAOQIZHISUAN_API_KEY}" \

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The notes claim 'No feudal superstitious content is involved,' yet the rest of the document clearly describes astrology/divination-style capabilities such as BaZi queries, Qi Men chart generation, and complete chart interpretation. This is an active contradiction in the skill's own documentation about the nature of the service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest description references authentication with "xiaoqizhisuan.cn MCP service," which implies a specific regional service context. For manifest files, natural-language policy issues include locale-related constraints that are forced or undocumented; this file does not explain whether the skill is region-specific or offer any user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.