Back to skill

Security audit

梅花易数技能

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a local Chinese divination tool with no hidden network or privilege behavior, though its optional saved history should be documented more clearly.

Use this skill as a local Chinese-language divination CLI. Be aware that using --save writes reading records and an index locally, and avoid saving sensitive health, relationship, finance, or dispute details unless you are comfortable retaining that history.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose is divination and analysis, but the implementation reportedly also stores local records, maintains an index, and searches historical entries. This mismatch is security-relevant because hidden persistence and retrieval can collect sensitive user inputs over time, surprise operators, and expand the attack surface beyond what the skill advertises.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill exposes code-capable behavior involving file reads and writes, but the manifest declares no explicit tool scope or permissions. This creates an authorization gap: consumers may trust the documented surface area while the implementation can access or persist local data without clear consent boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s user-facing description and instructions are entirely in Chinese, and there is no note that the skill is Chinese-only, region-specific, or that users may choose another language. This can violate a language/locale policy when a skill implicitly forces one language without user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill writes divination results, timestamps, question categories, and an index of prior readings to local disk without making this persistence prominent in the advertised functionality. Divination questions can reveal sensitive personal topics such as health, marriage, finances, or disputes, so silent retention creates a privacy risk if other local users, tools, or later skill actions access the stored files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code persists divination records locally with no user-facing warning that potentially sensitive query history is being stored. Because the skill supports intimate question categories and saves indexed metadata, this can unintentionally create a personal history dataset that may be read by others on the same system or mishandled later.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

User-facing descriptions, CLI help text, output labels, and status messages are all fixed in Chinese throughout the file. This enforces a specific language experience without any opt-in, fallback, or documented locale limitation, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill includes history browsing and search features over previously saved divination records, but those capabilities are not reflected in the manifest description. This increases privacy risk because users may not expect retained records to be discoverable later, especially for sensitive subjects like health, relationships, or finances.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.