Back to skill

Security audit

Bazi Full Fortune Telling

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Bazi fortune-telling skill, but users should treat the requested birth, family, health, relationship, and financial details as private.

Install only if you are comfortable using an agent for fortune-telling with birth and family context. You can skip calibration questions, answer at a high level, and ask the agent to show the report inline or confirm the exact save path before writing a txt file.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The README tells the agent to 'automatically load' the skill and be triggered by natural conversation without defining narrow invocation boundaries. In an agent environment, broad trigger language can cause unintended activation on unrelated user messages, increasing the chance of unnecessary sensitive-data collection or execution of local scripts.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The English usage section repeats the same problem by suggesting the agent will respond to general natural-language requests without constrained activation rules. This expands the chance of accidental invocation in multilingual environments and can lead to collection of personal birth and family details when the user did not intend to start the skill workflow.

Missing User Warnings

High
Confidence
96% confidence
Finding
The README instructs the agent to ask detailed calibration questions about parents, family economy, and life status but does not warn users that this is sensitive personal and family data. In a hosted or logged agent environment, collecting this information without clear notice and consent creates privacy and compliance risk, especially because the data concerns both the user and third parties.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The workflow directs output to a local txt file named from personal attributes without warning the user that sensitive analysis may be written to disk. Local persistence can expose private birth, family, and inferred-profile information to other local users, backups, sync services, or later compromise.

Missing User Warnings

High
Confidence
96% confidence
Finding
The English documentation asks the same sensitive calibration questions without any privacy notice or consent language. Because this broadens accessibility to more users, it increases the likelihood that sensitive family and life-stage data will be collected in contexts where users do not understand the privacy implications.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The English workflow says to output results as a txt file but does not warn that the file may contain highly personal information and inferred traits. Silent persistence of this content raises confidentiality risk and may violate user expectations in agent or shared-device environments.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger guidance is broad enough that an agent may invoke the skill for loosely related conversational inputs, causing unexpected collection of personal data or execution of local scripts. In an agent environment, unclear activation boundaries increase the chance of overreach and unintended tool use.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to write a local txt file without notifying the user or requesting consent. Silent filesystem writes can leak sensitive outputs, create persistence a user did not expect, and violate least-surprise expectations in agent systems.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The guide explicitly instructs the skill to ask for highly sensitive family and personal information, including parents' relationship status, parental absence, occupations, caregiving arrangements, and the user's education/work status, without any privacy notice, minimization guidance, or consent checkpoint. In a fortune-telling skill, this materially increases the risk of unnecessary collection of intimate personal data and can pressure users into revealing sensitive details under the guise of improving analysis.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to ask for highly sensitive family-status details, including divorce, parental absence, possible death, caregiving arrangements, and work/location information, without any warning, consent gating, minimization, or privacy notice. Even in a fortune-telling context, collecting this volume of intimate personal and family data can enable intrusive profiling and cause emotional harm if users are pressured into disclosing traumatic information.

Ssd 3

Medium
Confidence
96% confidence
Finding
The skill explicitly directs the agent to collect and use sensitive family and personal background details, including parental relationships, economic status, and current life situation. In an agent context, this creates unnecessary privacy risk, especially because the information is incorporated into generated outputs and may be persisted or exposed downstream.

Ssd 3

Medium
Confidence
97% confidence
Finding
The calibration workflow asks for highly sensitive personal and family details in plain language without any consent checkpoint, minimization, or handling guidance. Because the skill later instructs the agent to use this information in analysis artifacts, the risk of privacy intrusion and accidental disclosure is materially elevated.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.