Back to skill

Security audit

Rokusei

Security checks for vulnerabilities and agentic risk

Overview

This is a local birthday-based astrology skill with disclosed behavior and no evidence of hidden access, persistence, or data exfiltration.

Before installing, be aware that it runs local Node.js code and installs an npm dependency. It asks for a birth date and produces entertainment-oriented astrology output; do not treat its fortune, health, career, or relationship statements as professional advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Lines L091-L092 explain that 60 unique birthday signatures map to six planetary archetypes, but lines L095-L100 redefine the stars as simple contiguous numeric ranges '(1-10)', '(11-20)', etc. This is an internal documentation contradiction about how classification works, creating intent/code-description divergence within the skill documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest description explicitly defines the skill as a Japanese divination system, using Chinese and Japanese text, but provides no indication that users can choose language or locale. Under the policy rule for natural-language violations, locale constraints should be documented as optional or justified; this manifest does not make that explicit.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The dependency uses a caret range (^1.7.8), which permits automatic installation of newer compatible versions. If the upstream package is compromised or a malicious/broken release is published, installs may pull in unexpected code, creating a supply-chain risk; this is somewhat more relevant because the skill processes user-provided input and executes JavaScript at runtime.

Content

Scanner excerpt · package.json (reported line 10)May include surrounding context.

json
"start": "node scripts/rokusei.js"
  },
  "dependencies": {
    "lunar-typescript": "^1.7.8"
  },
  "keywords": ["rokusei", "六星占術", "占卜", "astrology", "japanese"],
  "author": "ikplpeter",

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code contains a natural-language comment stating the skill supports only zh, en, and ja. Under the locale-policy rule, forcing a fixed language set without explicit user opt-in can be a policy concern unless the restriction is clearly justified as region-specific or the user is offered a choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.