Back to skill

Security audit

Interpret Fate Via Ziwei

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Chinese Ziwei astrology guide, but it can expose a user's birth profile by default through a third-party URL without clear consent or privacy guidance.

Review this skill before installing if you are not comfortable sharing birth date, birth time, and sex in a generated third-party link. Prefer local chart calculation, and only open or request a populated online chart URL if you accept sending those details to ziwei.pub and having them appear in browser or conversation history.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:70
Finding

Personal Birth Data Embedded in a Third-Party URL

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 70-74
Vulnerability Type: Personal data exposure through URL query parameters
Risk Level: Medium

Vulnerable Code

text
## Output online chart URL

https://ziwei.pub/astrolabe/?d=<birth date, format YYYY-M-D>&t=<time index>&leap=<whether leap month, true or false>&g=<sex, male or female>&type=<calendar type, solar or lunar>

Technical Analysis

The Skill instructs the agent to construct a third-party URL containing the user's birth date, approximate birth time, sex, calendar type, and leap-month status in its query string. This information constitutes a personal birth profile.

URL query parameters can be disclosed through the destination server's access logs, browser history, chat transcripts, analytics systems, proxy logs, monitoring infrastructure, screenshots, and copied links. If the user opens the generated URL, the third-party service receives all encoded profile attributes. Even if the link is not opened, it remains exposed in the agent's output and any systems retaining that output.

The disclosure is unnecessary because the Skill separately specifies local chart calculation through the iztro package. The reviewed content does not establish malicious collection or automatic transmission, but the default generation of a personal-data-bearing external URL is an insecure privacy practice.

Attack Path

  1. The user supplies a birth date, birth time, sex, calendar type, and leap-month status.
  2. The agent follows SKILL.md and inserts these values into the prescribed ziwei.pub URL.
  3. The complete URL appears in the conversation and may be retained by chat logging or monitoring systems.
  4. If the user opens the URL, the browser sends the embedded information to the third-party website and its supporting infrastructure.
  5. Anyone with access to browser history, application logs, proxy l ...[truncated 666 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic generation of the third-party URL and use the local iztro calculation path by default.
  2. If the external service remains optional, obtain explicit informed consent before constructing or displaying the URL.
  3. Clearly identify the destination, the exact fields that will be disclosed, and the privacy implications before the user consents.
  4. Minimize transmitted data and avoid placing personal attributes in URL query strings. Prefer a privacy-preserving local workflow or, where supported, a consented POST request with appropriate retention controls.
  5. Do not persist the generated link in logs, telemetry, long-term memory, or analytics.
  6. Provide a redacted link template unless the user explicitly requests a populated external link.
  7. Document the third party's privacy and retention behavior before recommending the service.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill asks users for highly sensitive personal data, including full birth date/time and potentially birthplace, but provides no privacy notice, data minimization guidance, or explanation of how that data will be handled. In this context, the skill also instructs the agent to construct a third-party URL and run tooling based on the supplied data, which increases the risk of unnecessary exposure of personal information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill restricts gender input to a binary male/female choice without explaining why this is necessary or offering a respectful fallback. While not a classic security flaw, it can pressure users into disclosing sensitive identity information inaccurately and may lead to inappropriate handling of personal data in downstream processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The entire skill file is written in Chinese and provides no indication that other languages are supported or that the user can opt into this locale. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The entire skill file is written exclusively in Chinese and provides no indication of language selection, multilingual support, or justification for a Chinese-only requirement. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese from start to finish. Under the language/locale policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown skill document forces a specific language for all readers and does not provide any opt-in, alternative language, or stated region-specific justification. The policy explicitly calls for flagging language or locale constraints when the skill does not offer user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructional content in Chinese from start to end, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the language/locale policy, forcing a single language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents all instructional content exclusively in Chinese and does not indicate any user language choice or opt-in. Under the stated policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all instructional content in Chinese from the title onward and does not indicate that the language is optional or region-specific. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a locale/language policy concern.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says this skill interprets fate using Ziwei astrology principles, but this section inserts a fundraising advertisement asking readers to tip the site owner. Soliciting donations is not an obvious or necessary part of astrology interpretation and is therefore an unjustified capability within the skill's documented scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file consists exclusively of Chinese-language instructions and labels, and nowhere indicates that the user can choose another language or that the skill/document is intentionally limited to a Chinese-speaking audience. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.