Back to skill

Security audit

Chinese Almanac

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local Chinese almanac date-selection CLI with some overstated capability claims and broad triggers, but no evidence of hidden access, persistence, exfiltration, or destructive behavior.

Install only if you want a local, entertainment-oriented Chinese almanac date picker. Treat its results as traditional/interpretive guidance rather than authoritative advice, and be aware that the documentation appears broader than the actual scoring logic.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code generally aligns with the broad purpose of auspicious date selection and does compute results for marriage, business, moving, signing, travel, and similar activities. It clearly includes 建除十二神, 黄道黑道, and 彭祖-related data, so the core domain is correct. However, the declared description specifically claims integration of 天德、月德、天赦, which are not implemented anywhere in this code chunk. That is a material description-vs-behavior gap because these are presented as key components of the system, not minor details. Additionally, the implementation appears to be a simplified scoring/ranking CLI over a month, based mostly on day officer values and yellow/black classification, rather than a full classical almanac engine as strongly implied. This is best classified as a mismatch due to overstated declared functionality, even though the primary domain is related.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to activate on common conversational terms, which can cause unintended invocation of the skill. In an agent environment, overbroad routing can hijack unrelated user requests, degrade response integrity, and create opportunities for prompt-scope confusion even if the skill itself is non-malicious.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The listed triggers include ambiguous terms such as general calendar/date phrases and especially the Japanese term '時計' (clock/watch), which is unrelated and likely to match ordinary requests. This increases the chance of accidental skill activation and misrouting, making the skill more dangerous in context because it is intended for conversational triggering rather than explicit invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This file hard-codes Japanese UI labels alongside English and Chinese, which may contribute to a language/locale behavior being imposed elsewhere without an explicit user choice. Because the file itself is only localization data and does not show selection logic, the concern is limited but still reflects a potential locale-policy issue in natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The CLI initializes lang to en, which forces a specific language when the user does not opt in via --lang. This is a natural-language locale policy concern because the tool supports multiple languages but silently chooses one by default rather than prompting or negotiating user preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.