Back to skill

Security audit

奇门遁甲排盘系统

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local Chinese divination tool; it has an extra browser interface with CDN dependencies, but no evidence of hidden persistence, credential access, destructive behavior, or data exfiltration.

Installers should expect a Chinese-language, entertainment-focused Qimen Dunjia CLI tool. Use the Node command described in SKILL.md for local operation; avoid opening or distributing the HTML UI in sensitive contexts unless its external dependencies are pinned, integrity-checked, or vendored locally.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
qimen-dunjia.html:8
Finding

Unpinned Third-Party Scripts Execute Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: qimen-dunjia.html, lines 8–13
Vulnerability Type: Mutable remote dependencies without Subresource Integrity
Risk Level: Medium

Vulnerable Code

html
<!-- Core dependencies -->
<script src="https://unpkg.com/react@18/umd/react.production.min.js"></script>
<script src="https://unpkg.com/react-dom@18/umd/react-dom.production.min.js"></script>
<script src="https://unpkg.com/@babel/standalone/babel.min.js"></script>
<script src="https://cdn.tailwindcss.com"></script>
<!-- Icon library -->
<script src="https://unpkg.com/lucide@latest"></script>

Technical Analysis

When the HTML interface is opened, the browser downloads and executes JavaScript from unpkg.com and cdn.tailwindcss.com. None of these resources has a Subresource Integrity hash. Several URLs also use mutable version selectors, including @18, an unversioned package reference, and @latest.

Consequently, the code ultimately executed is not fully represented by the audited project. It may change when an upstream package release, CDN response, or package tag changes. HTTPS protects data in transit but does not ensure that future content at the same URL remains identical to the audited content.

This creates a third-party supply-chain exposure. Compromise of a referenced package, package publisher account, CDN, or mutable release could cause attacker-controlled JavaScript to execute in the page context.

Attack Path

  1. An attacker compromises a referenced package release, publisher account, CDN delivery path, or mutable package tag.
  2. The attacker causes one of the referenced URLs to serve modified JavaScript.
  3. A user opens qimen-dunjia.html while connected to the network.
  4. The browser retrieves the modified dependency because the page neither pins immutable reviewed artifacts nor verifies integrity.
  5. The malicious script executes with the privileges of JavaScript in the page context.
  6. It can alter displayed results, ...[truncated 835 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace floating dependency references such as @18 and @latest with exact, reviewed versions.
  2. Prefer vendoring the reviewed production builds inside the project and serving them locally.
  3. If CDN hosting remains necessary, add valid Subresource Integrity hashes and crossorigin="anonymous" to every external script that supports immutable assets.
  4. Avoid runtime Babel and the Tailwind CDN production helper. Precompile JSX and CSS during a controlled build process, then ship static generated assets.
  5. Introduce a restrictive Content Security Policy. Limit script-src to approved immutable sources and avoid allowances such as unsafe-eval where practical.
  6. Add dependency update review, lockfile verification, provenance checks, and automated vulnerability scanning to the release process.
  7. Recalculate and review integrity hashes whenever an intentionally pinned dependency is upgraded.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document declares lang="zh-CN", indicating a fixed Simplified Chinese locale. The UI text throughout the file is also presented exclusively in Chinese, with no visible language-selection or opt-in mechanism, which can violate language/locale choice policies.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The declared skill metadata says this is a command-line divination tool, but the file is a browser-based React application that pulls multiple third-party scripts from CDNs and includes a direct external contact prompt. This mismatch increases deception and trust risk because reviewers or users may expect a local, non-networked CLI skill but instead receive interactive web content with external dependencies and off-platform engagement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file header and all user-facing output strings indicate the tool is designed to operate exclusively in Chinese. Because the skill does not offer user opt-in or an alternative language/locale selection, it creates a language/locale policy concern under the natural-language policy rule.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.