Back to skill

Security audit

Real Ai Fortune Clawhub

Security checks for vulnerabilities and agentic risk

Overview

This fortune-telling skill is mostly coherent, but it can activate too broadly while collecting sensitive birth/location/home details and may steer high-impact health or legal questions toward an external human “master.”

Review before installing. Use it only when you intentionally want Chinese metaphysics entertainment content, and avoid sharing exact birth details, home photos, legal facts, medical details, or financial decisions unless you are comfortable with the skill’s unclear local-record handling and optional off-platform consultation framing. Do not treat its outputs or any referred “master” as a substitute for licensed medical, legal, financial, or mental-health advice.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation trigger is defined with very broad keywords like 算命、运势、fortune telling, which can cause the skill to invoke in loosely related conversations where the user did not explicitly request this metaphysics workflow. Unintended invocation is risky here because the skill collects sensitive birth/profile details and may steer users into deterministic scripts and off-platform human contact without sufficiently clear consent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger description is overly broad and can activate on generic terms like destiny, luck, fortune telling, or metaphysics outside a clearly bounded user intent. This increases the chance of unintended invocation, causing the agent to steer ordinary conversations into pseudoscientific guidance and potentially collect sensitive personal information unnecessarily.

Natural-Language Policy Violations

Medium
Confidence
98% confidence
Finding
Mandating a fixed Chinese opening script without language choice or opt-in can override user intent and force unsolicited ritualized framing before any clarification. This is risky in multilingual or sensitive contexts because it may confuse users, reduce informed consent, and make the skill feel more authoritative or coercive than appropriate for entertainment-oriented content.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The usage guidance contains an ambiguous catch-all condition ('任何涉及传统命理规则计算的场景'), which lacks practical scope limits and may cause the skill to engage in contexts the user did not clearly request. In this skill, that matters more because subsequent workflow asks for sensitive birth, location, and situational data and may influence decisions in health, legal, or financial-adjacent contexts.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes very broad Chinese terms such as '算命', '风水', '命理', and '运势', which can match a wide range of ordinary conversations and cause the skill to activate outside the user's clear intent. Because this skill offers quasi-advisory spiritual guidance and routes users into a human/AI consultation flow, unintended invocation can steer unrelated conversations into manipulative or misleading content.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The English triggers 'bazi', 'meihua', 'feng shui', and especially 'fortune telling' are generic and lack invocation context, making accidental activation likely in educational, historical, or casual discussion. In a skill that presents deterministic outputs plus human-master interpretation, overbroad triggering increases the risk of unsolicited persuasive guidance and confusing users about when the system is intentionally entering this mode.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The file mandates that the AI display third-party instructions verbatim before proceeding and forbids summarization or omission. This bypasses normal conversational safeguards such as language selection, consent, accessibility adaptation, and policy-aware reframing, creating a prompt-injection style control channel where embedded content can steer user interaction without review.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The module docstring and all user-facing usage instructions are written only in Chinese, and the CLI description/output are likewise Chinese-only. This imposes a fixed language experience without offering the user any language or locale choice, which matches the policy violation criteria for forced language/locale.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The argparse description, error message, and normal output strings are all hard-coded in Chinese. Because the skill does not offer opt-in language selection or state a justified locale restriction, this is a natural-language policy issue.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
The module docstring, CLI examples, argument values, and user-facing output are all presented only in Chinese, and the gender input is restricted to Chinese values such as “男” and “女”. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation when no alternative locale or language choice is offered.

Static analysis

No suspicious patterns detected.