Back to skill

Security audit

Astro Daily Transits

Security checks for vulnerabilities and agentic risk

Overview

This astrology chart skill is mostly coherent, but it changes the runtime environment and embeds promotional QR/link content by default without enough user control.

Review before installing. Use this only in an isolated environment where runtime package installation and native Windows extensions are acceptable. Avoid sharing generated charts unless you are comfortable with the default QR code and ClawHub URL being included, and be cautious if another astro-natal-chart skill directory exists nearby because this skill may import code from it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

other

Error
Location
scripts/draw_daily.py:404
Finding

Unsolicited promotional URL and QR code embedded in generated charts by default

Content
View full analysis
- **QR code now renders by default** — --frame defaults to bundled scripts/frame_small.png.dat. QR ...[truncated 2337 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/draw_daily.py:15
Finding

Unpinned runtime installation of Pillow through pip

Content
View full analysis
| **Pillow** | **12.x** — `pip install pillow` | ``` ### Technical Analysis If Pillow cannot be imported, normal renderer execution invokes pip and installs the package named `pillow`. The installation command provides no exact version, package hash, locked artifact, index restriction, or user confirmation. The documentation states a requirement for Pillow 12.x, but the executed command does not enforce that version range. The package selected at runtime can therefore vary according to installation date, pip configuration, configured package indexes, mirrors, dependency resolution, and upstream package state. Python package installation can execute build-system and installation logic. Automatically invoking pip from normal application code expands chart rendering into a dependency acquisition and code-execution operation. This creates a supply-chain boundary that is not adequately controlled. No evidence was found that the current Pillow package is malicious. The vulnerability is the unsafe and mutable dependency acquisition process. ### Attack Path 1. The renderer starts in an environment where `PIL` is unavailable or intentionally made unavailable. 2. The `ImportError` handler invokes `python -m pip install pillow -q`. 3. Pip resolves the package through the environment's configured index or mirror. 4. A compromised index, mirror, account, DNS path, package release, or local pip configuration supplies attacker-controlled package content. 5. Package build or in ...[truncated 677 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/draw_daily.py:40
Finding

Executable Python module imported from an unverified external sibling directory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
| **Swiss Ephemeris** | Bundled as `swisseph.cp314-win_amd64.pyd.dat` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

md
| **Swiss Ephemeris** | Bundled as `swisseph.cp314-win_amd64.pyd.dat` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

md
| `seguisym.ttf.dat` | Zodiac symbols ♈♉♊... + aspect symbols ☌☍△□... | `.dat` (ClawHub-compatible) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 237)May include surrounding context.

md
| `seguisym.ttf.dat` | Zodiac symbols ♈♉♊... + aspect symbols ☌☍△□... | `.dat` (ClawHub-compatible) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 224)May include surrounding context.

md
| `segoeuisl.ttf.dat` | Cyrillic, latin, digits | `.dat` (ClawHub-compatible) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 238)May include surrounding context.

md
| `segoeuisl.ttf.dat` | Cyrillic, latin, digits | `.dat` (ClawHub-compatible) |

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The changelog states that a QR code is rendered by default and references a --frame option that is not documented elsewhere, creating a mismatch between documented behavior and actual output. If the rendered QR encodes a link or forecast-related data, users may unknowingly distribute images containing hidden or unexpected machine-readable content, which is a security and privacy issue because it alters output semantics without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

An always-on QR code embedded in generated forecast images can create an undisclosed data exposure channel, especially in a skill that processes birth date, time, city, name, and derived personal forecast content. Even if the QR only links externally, failing to warn users about its presence and contents can cause accidental sharing of sensitive or tracking-related metadata when the image is redistributed.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
86% confidence
Finding

The file contains mixed-script content, including a likely confusable key ("Neptун") where Cyrillic characters are mixed into an otherwise Latin identifier. This is dangerous because homoglyphs can hide logic discrepancies, make reviews unreliable, and cause security-sensitive mappings or checks to behave differently than expected without being obvious to maintainers.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The CLI offers --lang choices ru and en at L410, but generate_forecast(..., lang="ru") ignores that choice and emits fixed Russian text throughout the forecast body and summary. This is a natural-language locale policy issue because the skill presents a language option without actually honoring user opt-in for English output.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The renderer changes the execution environment by installing a package at runtime, a capability not necessary for safe rendering once dependencies are provisioned correctly. In a skill setting this is more dangerous because execution may occur on shared or sensitive hosts where network access and package installation should be tightly controlled.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
96% confidence
Finding

If Pillow is missing, the script automatically runs pip install at runtime, which modifies the host environment and pulls code from package repositories during normal execution. In an agent or automation context, this creates an unexpected code acquisition path and dependency-supply-chain risk, especially without user approval or pinned, verified artifacts.

Content

Scanner excerpt · scripts/draw_daily.py (reported line 18)May include surrounding context.

python
try:
    from PIL import Image, ImageDraw, ImageFont
except ImportError:
    subprocess.check_call([sys.executable, "-m", "pip", "install", "pillow", "-q"])
    from PIL import Image, ImageDraw, ImageFont

# ─── Copy .dat → usable ───

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Auto-installing Pillow via pip without warning or confirmation introduces silent environment mutation and a package supply-chain trust decision during execution. In agent contexts, this can bypass deployment controls, unexpectedly use network access, and expose the system to malicious or compromised dependencies.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script silently writes bundled .ttf.dat, .pyd.dat, and .png.dat files back to executable/resource filenames in the script directory. Writing .pyd files is especially sensitive because it reconstructs native Python extension modules on disk, which can enable hidden code-loading behavior and bypass expectations about what artifacts the skill creates.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/draw_daily.py (reported line 909)May include surrounding context.

python
if args.name:
        cmd.extend(["--name", args.name])

    res = subprocess.run(cmd, capture_output=True, text=True, timeout=30,
                         cwd=_SCRIPTDIR, encoding="utf-8")
    if res.returncode != 0:
        print("Error:", res.stderr or res.stdout)

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Beyond rendering astrology content, the code adds a QR image labeled for donations and later prints a ClawHub URL into the generated output. This promotional capability is not justified by the apparent rendering purpose and expands behavior beyond producing the chart itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

If provided, the --conclusion argument causes the script to open and read a local file whose contents are embedded into the rendered output. This local file access is not accompanied by a warning or disclosure in code comments or user-facing output.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/daily_transits.py:41