Back to skill

Security audit

Astro Lunar Insights

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches its astrology-chart purpose, but it automatically installs/copies executable dependencies and uses weak temporary-file handling for personal birth data.

Review before installing. Use an isolated Python environment, preinstall a pinned Pillow version yourself, and only run the bundled Windows native Swiss Ephemeris binary if you trust the publisher and package source. Be aware that generated charts include donation/promotional content by default and that birth details may be written to temporary JSON and output image files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
scripts/draw_lunar.py:711
Finding

Forced Promotional URL and Donation QR Code in Generated Output

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/draw_lunar.py:11
Finding

Automatic Installation of an Unpinned Package at Runtime

Content
View full analysis
Remediation
View remediation
`. 4. Use a lock file with SHA-256 hashes and install with hash enforcement. 5. Configure an explicit trusted package index rather than inheriting arbitrary pip configuration. 6. Install dependencies in a restricted virtual environment before Skill execution. 7. Fail safely with a clear dependency error when Pillow is unavailable instead of downloading code automatically. 8. Incorporate dependency vulnerability and integrity scanning into release preparation. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/draw_lunar.py:926
Finding

Predictable Shared Temporary File Allows Race Conditions and File Clobbering

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/draw_lunar.py:18
Finding

Bundled Native Extension Is Activated Without Integrity Verification

Content
View full analysis
os.path.getmtime(_dst): shutil.copy2(_src, _dst) ``` The analysis engine then imports the resulting native module: ```python import swisseph as swe ``` The bundled source artifact is: ```text scripts/swisseph.cp314-win_amd64.pyd.dat ``` After the generic extension stripping, it becomes: ```text scripts/swisseph.cp314-win_amd64.pyd ``` ### Technical Analysis The renderer copies every `.dat` file in the scripts directory to a filename with `.dat` removed. This activates the bundled Swiss Ephemeris artifact as an importable Windows native extension. Importing a `.pyd` module executes native machine code during module initialization. The code does not verify a cryptographic digest, package signature, trusted publisher, or expected file size before copying and importing the component. The use of a generic loop also expands the attack surface: any future `.dat` file placed in the directory is automatically copied to its extension-stripped form. This behavior is broader than the stated requirement to activate specific fonts and the Swiss Ephemeris binary. The audit confirmed the activation path but could not verify the full behavior of the compiled native binary from Python source. This finding therefore concerns unsafe trust and loading practices, not a claim that the reviewed b ...[truncated 1144 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (20)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
| **Swiss Ephemeris** | Bundled as `swisseph.cp314-win_amd64.pyd.dat` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 278)May include surrounding context.

md
| **Swiss Ephemeris** | Bundled as `swisseph.cp314-win_amd64.pyd.dat` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 265)May include surrounding context.

md
| `seguisym.ttf.dat` | Zodiac symbols ♈♉♊... + planet symbols ☉☽☿... | `.dat` (ClawHub-compatible) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 279)May include surrounding context.

md
| `seguisym.ttf.dat` | Zodiac symbols ♈♉♊... + planet symbols ☉☽☿... | `.dat` (ClawHub-compatible) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 266)May include surrounding context.

md
| `segoeuisl.ttf.dat` | Cyrillic, latin, digits | `.dat` (ClawHub-compatible) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 280)May include surrounding context.

md
| `segoeuisl.ttf.dat` | Cyrillic, latin, digits | `.dat` (ClawHub-compatible) |

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/draw_lunar.py (reported line 929)May include surrounding context.

python
# Get JSON data — write to temp file to avoid console encoding issues
    import tempfile
    tmp_json = os.path.join(tempfile.gettempdir(), "lunar_analysis_tmp.json")
    env = os.environ.copy()
    env['PYTHONIOENCODING'] = 'utf-8'
    res = subprocess.run(
        [sys.executable, os.path.join(script_dir, "lunar_analysis.py")] + analysis_args + ["--output", tmp_json],

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Unbounded Output

Medium
Category
Output Handling
Confidence
74% confidence
Finding

The documentation states that AI mode renders supplied interpretation text 'without truncation', which can permit oversized untrusted content to flow into rendering. If an upstream agent or input file provides extremely large text, this can cause excessive memory use, rendering failures, denial of service, or unusable output artifacts.

Content

Scanner excerpt · SKILL.md (reported line 344)May include surrounding context.

md
- `string` — plain text interpretation (AI mode)

The renderer (`draw_text_panel`) automatically detects the format and extracts
the text accordingly. AI mode shows full text without truncation; autonomous mode
limits text to keep the chart compact.

## AI Workflow (for OpenClaw agents)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The SKILL.md includes a hard requirement in Russian that agents must always provide extended AI interpretation when possible, and the documented workflow renders the conclusion with --lang ru. This natural-language instruction forces a specific language/locale behavior for agent use without presenting it as a user-selected option, which violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Unbounded Output

Medium
Category
Output Handling
Confidence
76% confidence
Finding

The changelog confirms the same behavior: AI text is displayed in sections 1–8 without truncation. Reiterating this design indicates the renderer intentionally accepts unbounded text from external AI-generated JSON, increasing the risk of denial of service and layout/resource exhaustion when handling adversarial or malformed input.

Content

Scanner excerpt · SKILL.md (reported line 449)May include surrounding context.

md
each with `interpretation` field; `overall` field for section 9 summary only
- **Helper functions `interp_text()` and `show_interp()`** in `draw_text_panel`:
  unified extraction of interpretation text from dict, tuple, or string formats
- **AI mode:** full text displayed without truncation in sections 1–8; section 9 shows only `overall`
- **Autonomous mode:** preserved with text limits for compact layout
- **Section 8 (Aspects):** added AI interpretation of transit Moon aspects after the aspect list
- **Conclusion JSON format documented** in SKILL.md with examples for all supported formats

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The script installs pillow at runtime via pip if the import fails, which adds package-management and likely network capability during normal execution without user consent. This expands the trust boundary to package indexes and the local Python environment, creating supply-chain and integrity risks if package sources or the environment are compromised.

Content

Scanner excerpt · scripts/draw_lunar.py (reported line 14)May include surrounding context.

python
try:
    from PIL import Image, ImageDraw, ImageFont
except ImportError:
    subprocess.check_call([sys.executable, "-m", "pip", "install", "pillow", "-q"])
    from PIL import Image, ImageDraw, ImageFont

# в”Ђв”Ђ Font + binary setup в”Ђв”Ђ

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

A renderer should not silently gain package-install and potential network behavior at runtime; doing so materially increases attack surface beyond its chart-rendering purpose. If an attacker can influence package resolution, indexes, or the local Python environment, this behavior could lead to untrusted code execution or environment tampering.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Silently installing a Python package at runtime without warning or confirmation is risky because it changes the host environment and may fetch executable code from external repositories. In restricted or sensitive environments, this can violate least privilege and create an unexpected remote code supply-chain path.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/draw_lunar.py (reported line 931)May include surrounding context.

python
tmp_json = os.path.join(tempfile.gettempdir(), "lunar_analysis_tmp.json")
    env = os.environ.copy()
    env['PYTHONIOENCODING'] = 'utf-8'
    res = subprocess.run(
        [sys.executable, os.path.join(script_dir, "lunar_analysis.py")] + analysis_args + ["--output", tmp_json],
        capture_output=True, text=True, timeout=30, cwd=script_dir, encoding="utf-8", env=env
    )

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The file advertises bilingual support, which is acceptable, but it does not clearly state whether the tool defaults to one language or how locale is selected when --lang is omitted. Because language/locale policy issues apply to natural-language instructions, this is a mild documentation concern if the implementation forces a language without explicit user choice.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Beyond rendering lunar analysis content, the code adds a ClawHub URL and optionally pastes a QR-code-style frame image into the final chart. For an unknown-purpose but apparently analytical renderer, this is an extra capability not inherent to chart generation or interpretation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The CLI restricts --lang to only "en" and "ru", which is a natural-language locale constraint. The file does not document a policy justification for limiting output to these languages beyond implementation choice, so this may conflict with language-choice expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code performs a file write when --output is provided, but there is no confirmation prompt or explicit warning near the write operation that user data will be saved to disk. For a code file, file writes are in scope when they lack visible disclosure, and the surrounding docstring only generally mentions outputs without warning that personal birth data and conclusions may be written to a user-specified file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script's natural-language interface and reports are effectively limited to English by default, with Russian as the only alternate locale. This can be a language/locale policy concern because the skill imposes a specific output language unless the user knows to opt into the limited alternative.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.