Back to skill

Security audit

MBTI Personality Test - MBTI性格测试

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward MBTI quiz skill that uses JisuAPI as disclosed, with the main privacy consideration that quiz answers are sent to that third-party API.

Install only if you are comfortable using JisuAPI for MBTI scoring. Your API key is read from JISU_API_KEY, and quiz answers or answer codes are sent to JisuAPI to produce the result; avoid using it for highly sensitive personal assessments unless that third-party handling is acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares runtime requirements including an environment variable and relies on an external API, but it does not declare an explicit tool scope such as allowed tools or permissions. That creates a governance gap: an agent may invoke code with network access and secret handling without clear policy boundaries, increasing the chance of over-broad execution or unintended secret exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation guidance is broad enough that the skill may trigger on generic personality-test or MBTI-related requests without clearly confirming the user's intent to use this third-party-backed workflow. Mis-triggering can unnecessarily route user interaction and responses into this skill, which matters more here because answers are later sent to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill collects questionnaire answers and submits them to a third-party API but does not prominently warn users that their responses will leave the local system. Personality-test answers can reveal sensitive personal traits or preferences, so the lack of transparent disclosure undermines informed consent and creates privacy risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This skill sends user test interactions to a third-party API endpoint, which is an external transmission of potentially sensitive personality-assessment data. While HTTPS is used and this is necessary for the skill’s functionality, users may not expect their answers and derived personality data to be shared with an external service, creating privacy and data-handling risk.

Content

Scanner excerpt · character.py (reported line 16)May include surrounding context.

python
import requests


QUESTIONS_URL = "https://api.jisuapi.com/character/questions"
ANSWER_URL = "https://api.jisuapi.com/character/answer"

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The answer submission endpoint transmits the compiled MBTI answer string to an external service, directly exposing user-provided assessment responses and enabling third-party profiling. In the context of a personality-test skill, this is more sensitive than a generic lookup because the data can reveal inferred traits and preferences.

Content

Scanner excerpt · character.py (reported line 17)May include surrounding context.

python
QUESTIONS_URL = "https://api.jisuapi.com/character/questions"
ANSWER_URL = "https://api.jisuapi.com/character/answer"


def _normalize_version(version: Any) -> str:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The interactive quiz prompts and validation messages are hard-coded in Chinese, requiring users to interact in a specific language. The file does not offer a language choice or document that the skill is intentionally limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.