Back to skill

Security audit

Bazi Full Fortune Telling

Security checks for vulnerabilities and agentic risk

Overview

This astrology skill is not malware, but it asks for detailed birth, family, health, finance, and life-event information and instructs saving a sensitive report to a text file without clear privacy controls.

Review before installing. Use it only if you are comfortable sharing exact birth time, birthplace, family background, and life-event details for fortune-telling. Avoid unnecessary names or third-party family details, and tell the agent not to save a TXT report unless you explicitly choose a safe location. Treat health, legal, and financial outputs as cultural/entertainment analysis, not professional advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises a full-featured Bazi analysis skill with multiple analytical subsystems and optional cross-system verification. The supplied code chunk only constructs a Bazi object from lunar input and formats it as Markdown via external library calls. While chart generation is consistent with part of the description ('排盘引擎'), the implementation shown does not substantiate the broader claimed capabilities. This is therefore a material description-to-behavior mismatch, with the actual code representing only a limited subset of the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a full-featured 八字命理 analysis skill centered on four-pillars astrology and extensive interpretive rules. The supplied code does not implement any of that. It simply accepts a date, validates it, invokes getChineseCalendar / getChineseCalendarMarkdown from an external library, and outputs the Chinese calendar information. While the declaration briefly mentions 查黄历, that is only a small sub-point inside a much broader BaZi-analysis description; this code’s primary and only evident purpose is calendar lookup, not fortune analysis. Therefore the actual behavior is materially narrower and different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description centers on 八字/四柱八字 analysis as the main skill, with Ziwei Doushu only as an optional cross-check. However, the code chunk only implements a Ziwei-specific calculator and validator for 安紫微星, using a formula based on bureau number and day number, then printing verification output and markdown tables. There is no code for parsing user intent, no Bazi chart engine, no ten-gods or five-elements strength analysis, no luck-year/decade computation, and no comprehensive fortune-reading templates. Because the actual code is narrowly focused on Ziwei verification and lacks the declared core Bazi capabilities, this is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: bazi-full-fortune
description: >
  八字全方位算命 Skill — 排盘引擎 + 六亲十神规则 + 家庭校准 + 回测校验 + 八大维度
  全方位分析模板。当用户提到八字、四柱、四柱八字、天干地支、日主、十神、大运流年、
  喜用神、忌神、格局、身强身弱、五行旺衰、伤官配印、食神生财、排盘、反推阳历、
  查黄历、命局分析等相关内容,或想了解命运、性格、事业、婚姻、财运、健康、学业
  且明确要求或暗示使用八字体系时,触发此技能。支持可选的紫微斗数交叉验证以提�

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
node scripts/scan_year.ts 2000 0 \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
node scripts/scan_year.ts 2000 0 \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
node scripts/scan_year.ts 2000 0 \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 160)May include surrounding context.

md
node scripts/scan_year.ts 2000 0 \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to collect highly sensitive personal and family information, including birth details, family structure, work status, and life events, without any privacy notice, consent language, minimization guidance, or retention policy. In an agent context, this is dangerous because users may reveal intimate data under the assumption it is required, and the documentation gives no warning about sensitivity, storage, or downstream exposure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow documentation states in Step 7 that the skill will output a txt file named 八字全解_日主X_生肖X.txt. However, the project structure and usage sections list only charting, calendar, reverse-lookup, and optional Ziwei verification scripts, with no report-generation or file-writing script documented. This creates a manifest/documentation-to-implementation mismatch about a concrete side effect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README instructs generating a TXT file containing a full destiny analysis tied to birth data and inferred personal details, but does not warn the user that sensitive data may be written to disk. This creates a confidentiality risk because local files can persist unexpectedly, be indexed, synced, or accessed by other users or processes on the system.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are very broad and include many common astrology-related terms, which can cause the skill to activate in unintended contexts and solicit or process sensitive birth, family, and health information. In an agent ecosystem, overbroad triggering increases the chance of accidental invocation, privacy over-collection, and misleading users about when specialized handling is occurring.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs collection and generation of highly sensitive personal inferences about health, family relationships, finances, and intimate life, but it does not provide a clear privacy notice, consent flow, or data-minimization guidance. This is dangerous because users may disclose birth data and family details without understanding that the skill will derive and present sensitive personal profiles.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Requiring export of a full reading to a local TXT file creates a persistent artifact containing birth data and sensitive inferred attributes, yet the skill does not warn about local data exposure. If the host device is shared, backed up, indexed, or synced, this can leak personal information well beyond the original session.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file explicitly mandates Chinese output for all responses, regardless of the user's language preference. This can override user intent or platform locale expectations, causing confusing or inaccessible responses and reducing transparency in multilingual environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document is entirely written as Chinese-only operator guidance and includes direct user-facing question templates only in Chinese. There is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file instructs the agent to proactively ask for intimate family-history details such as divorce, parental absence, death, remarriage, fostering, and work/location data without any warning, minimization, or consent framing. In a fortune-telling context, these questions can pressure users into disclosing highly sensitive personal and third-party information that is not strictly necessary unless the user explicitly opts in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs collection of highly sensitive personal data including full birth date, birth time, sex, and birth city, which together are strong identifying attributes and are not accompanied by a privacy notice, minimization guidance, retention limits, or safer alternatives. In this context, the data is not just sensitive but also more dangerous because the skill encourages gathering enough detail to uniquely identify a person while framing it as mandatory for service delivery.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file directs the agent to collect family structure, parental employment, caregiving history, and current life stage for 'calibration' without warning that these are sensitive profiling attributes. This creates unnecessary exposure of intimate personal and household information that could be misused for social engineering, re-identification, or invasive profiling, especially when combined with the birth data collected earlier.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire document is written in Chinese and provides operational guidance only in that language, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, a forced language or locale without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template explicitly requests a broad set of highly sensitive personal data, including name, sex, birthplace, birth date, and exact birth time, without any privacy warning, minimization guidance, or handling constraints. In this skill’s context, these fields are not just generic profile data: together they create a strong personal identifier set that can expose users to profiling, deanonymization, and unnecessary collection of sensitive personal information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script accepts only 0 (female) or 1 (male) and enforces that constraint in user-facing validation text. This is a natural-language policy concern because it forces a specific gender model without documenting user opt-in or a justified region/compliance constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The README states that model quality is ranked partly by Chinese comprehension and frames the project around Chinese-language usage, while not explicitly offering language or locale choice to users. This can be a language-policy issue when a skill appears to assume a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

整个技能描述、触发方式、输出模板和文件名均默认固定为中文,没有说明是否支持其他语言或允许用户选择输出语言。按组织语言/locale 政策,若技能限定特定语言而无用户 opt-in,属于自然语言策略风险。

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Telling users to 'just speak to the Agent to trigger' without clear scope or boundaries can lead to implicit activation and unconsented handling of sensitive data. While not severe on its own, it weakens user awareness and control over when the skill is engaged.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.