Security audit
风水堪舆技能
Security checks for vulnerabilities and agentic risk
Overview
This feng shui skill appears security-benign, though it may not work as packaged because the documented script is missing and the JavaScript has syntax errors.
From a security perspective this skill is low risk because it does not ask for sensitive access or perform network, file, shell, or persistence operations. Before installing, expect possible breakage until the publisher fixes the missing documented script or the invalid JavaScript syntax.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
