Back to skill

Security audit

Big8 · 算八字·玄学算命助手(八字排盘·算命·风水·面相·星座·每日一卦)| Chinese Fortune Telling, Feng Shui & BaZi

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese fortune-telling assistant whose sensitive photo and birth-date handling is mostly disclosed and aligned with its stated purpose, with some privacy and dependency cautions.

Install only if you are comfortable using an entertainment-oriented Chinese metaphysics tool with birth dates, selfies, and room photos. Avoid uploading other people's photos, treat outputs as entertainment rather than medical, legal, financial, or life decisions, and run any Python dependency installs in a pinned virtual environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
big8-plan.md:46
Finding

Unpinned and Unnecessary Third-Party Dependencies

Content
View full analysis

Vulnerability Details

File Location: big8-plan.md:46
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

text
pip install lunar-python pillow

Technical Analysis

The documented installation command retrieves mutable latest versions of lunar-python and pillow from the configured Python package index. It provides no exact version constraints, cryptographic hashes, or lockfile. Consequently, the installed code can change after this project has been reviewed.

Python packages may execute build or installation logic with the privileges of the user running pip. If a resolved package release or package index is compromised, following this instruction could execute attacker-controlled code.

scripts/big8.py imports lunar_python, making that package necessary for the declared functionality. No reviewed project file imports or otherwise uses Pillow, so installing pillow unnecessarily increases the dependency and supply-chain attack surface.

This finding does not establish that either named package is currently malicious. The vulnerability is the unsafe, non-reproducible dependency installation practice.

Attack Path

  1. A user follows the installation instruction in big8-plan.md.
  2. pip queries the user's configured package index and resolves the latest available releases and transitive dependencies.
  3. An attacker compromises a future release, its maintainer account, an applicable package index, or a transitive dependency.
  4. pip downloads and installs the compromised artifact.
  5. Malicious build or installation logic executes with the invoking user's privileges.
  6. The malicious package may then persist as imported application code or modify resources accessible to that user.

Impact Assessment

Exploitation could obtain the permissions of the account running pip. Depending on that account and environment, the comprom ...[truncated 509 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove pillow from the installation instructions unless the implementation begins to use it.
  2. Pin lunar-python to an exact, reviewed version rather than accepting the latest release.
  3. Record dependencies in a dedicated requirements or lock file.
  4. Require verified hashes for all direct and transitive artifacts, for example by using pip install --require-hashes -r requirements.txt.
  5. Generate and review a fully resolved dependency lock so transitive dependency changes cannot occur silently.
  6. Install dependencies inside a dedicated virtual environment under a non-privileged account.
  7. Use a trusted, explicitly configured package index and consider an internally mirrored repository containing approved artifacts.
  8. Add automated dependency vulnerability and integrity scanning to the release process.

Example hardened requirement:

text
lunar-python==<reviewed-version> --hash=sha256:<verified-hash>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill promises privacy-preserving image analysis and broad functionality that the implementation apparently does not provide, while also omitting disclosure of local file storage for hexagram state. This mismatch can mislead users into sharing sensitive selfies, room photos, and birth data under false assumptions about processing and retention, which is a security and privacy risk even without overtly malicious code.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill instructs the agent to read local knowledge files and invoke local scripts, but it does not declare any explicit tool scope or permissions boundary. That creates an authorization gap where the runtime may permit broader file access than users or platform policy expect, increasing the chance of unintended file reads or writes beyond the intended knowledge base.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad, common-language terms such as '算命', '风水', and '星座', which can cause the skill to activate in conversations where the user did not intend to invoke it. Unintended invocation matters here because the skill solicits sensitive personal data and may initiate privacy-impacting analysis paths based on casual phrases.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Defaulting to the server timezone and locale without opt-in can produce incorrect divination, almanac, or date-based outputs for users in other regions. In this skill's context, that can mis-handle birth times and daily calculations, causing privacy-relevant inference errors and misleading personalized outputs tied to sensitive personal data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The intent-recognition logic treats any attached image as a signal to automatically classify and analyze it, including faces and indoor scenes, without a clear opt-in boundary. That is dangerous because it can lead to unsolicited processing of biometric-like facial data and private household images, especially in mixed-purpose chats where an image was shared for another reason.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The plan explicitly processes user selfies to infer facial attributes and then produce face-reading judgments, which involves highly sensitive image data and potentially biometric-like analysis. Although it claims images are discarded and not sent to third parties, the warning is minimal and does not provide clear, informed consent, retention details, model-processing scope, or safeguards for sensitive inferences, making this a real privacy issue.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · big8-plan.md (reported line 76)May include surrounding context.

md
| 文件 | 说明 |
|:--|:--|
| `skills/big8/SKILL.md` | 技能描述 + 使用说明 |
| `skills/big8/scripts/big8.py` | 主脚本(路由 + 逻辑) |
| `skills/big8/scripts/knowledge/` | 知识库目录 |
| `skills/big8/.clawhub/` | ClawHub 发布配置 |

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring and CLI expose only four commands: bazi, zodiac, gua, and huangli. There is no code for handling uploaded images, face analysis, or home-layout feng shui analysis, so the implemented behavior materially falls short of the manifest's described capabilities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The title, usage instructions, error messages, and output labels are all presented in Chinese, which imposes a specific language on users by default. There is no opt-in, alternative language support, or justification that this tool is intentionally limited to a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill content is written in Chinese and provides no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. Under the policy rule, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This manifest-style YAML file uses Chinese throughout and does not indicate that the skill is region-specific or that users may opt into another language. Under the language/locale policy, forcing a specific language without user choice or justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description promises '星座运势与配对' (horoscope fortune and compatibility), which implies richer astrology functionality. The implemented zodiac logic only maps a birth date to a sign and element, without any luck/fortune, compatibility, or pairing analysis.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest describes a fortune-telling assistant, but does not indicate that the skill writes a local state file to force the same result per day. While persistence supports the feature, it is still additional behavior beyond the plainly described 'daily hexagram' interaction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code creates and writes .big8_gua_state.json in the script directory to persist the daily divination result. Although the file operation is documented in an internal comment/docstring, there is no user-facing disclosure in CLI output or usage text that running gua will create local state on disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This YAML knowledge base is entirely authored in Chinese, including headings, keys, and explanatory values, with no indication that the skill is region-specific or that users may opt into another language. The policy requires flagging language or locale constraints when a skill effectively forces a specific language without user choice or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This YAML knowledge file is entirely written in Chinese, including headings, keys, and content values, with no indication that the skill is region-specific or that users can opt into this locale. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be a locale policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.