Back to skill

Security audit

☯ Big8 · 玄学算命助手(八字·算命·风水·面相·星座·每日一卦)| Chinese Fortune Telling, Feng Shui & BaZi

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly malicious, but it asks users to submit face photos for personal inferences while making an unclear privacy claim about where those images are processed.

Install only if you are comfortable with face photos and room images being analyzed by the agent's vision model. Treat the readings as entertainment, avoid uploading images of other people without consent, and do not rely on the privacy promise unless the runtime clearly confirms where images are processed and whether they are retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The plan claims face images are 'not uploaded to any third party' while also stating they are sent to a Vision Model for analysis, which is a direct contradiction unless the model is fully local and under the operator's control. This is dangerous because it can mislead users about biometric-data handling, undermine consent, and create privacy/compliance exposure if selfies are transmitted to external services.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The feature performs face-reading from selfies and infers personal attributes from facial characteristics, but the plan does not provide a clear warning about biometric processing, sensitive inferences, accuracy limits, or potential harms. In this context, users may share highly sensitive images without informed consent, especially since the product markets the feature as playful and easy to use.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.