Back to skill

Security audit

河洛理数 · 一卦定终身

Security checks for vulnerabilities and agentic risk

Overview

This is a local Chinese fortune-chart skill that asks for birth details and runs local calculation scripts, with some privacy and data-quality caveats but no hidden exfiltration, persistence, or credential access found.

Install only if you are comfortable providing birth date/time, approximate birthplace, and gender for a divination-style reading. Treat outputs as entertainment, be aware the skill is Chinese-language focused, and verify results because the bundled reference data has at least one confirmed mislabeled section.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code substantially matches the domain and core computational purpose of a 河洛理数 engine: it calculates 本命卦、后天卦、元堂、大运 and 流年 structures. However, the declared description promises a full skill workflow that first gathers missing user inputs interactively, including birth location, and then produces year-by-year interpretive judgments. This code does not implement any dialogue behavior, missing-field checks, or location handling. It also explicitly states it only performs algorithmic calculation and does not embed 爻辞/卷四 interpretive data, so it cannot by itself deliver the described detailed fortune commentary. Therefore the description overstates important user-facing capabilities relative to the supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description promises a full 河洛理数 workflow centered on natal hexagram and life-fortune analysis, including collection of birthplace and gender and calculation of long-term luck cycles and annual predictions. The code shown is a standalone CLI script for 八字排盘: it computes 年柱、月柱、日柱、时柱 from a Gregorian date and hour using fixed calendrical rules (五虎遁、五鼠遁、节气边界 approximations) and prints them. This is related birth-chart support logic, but it is materially narrower than and different from the declared primary purpose. There are no signs of undeclared sensitive behavior, but there is a clear description-vs-behavior mismatch because the major promised capabilities are absent from this code chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
> ⚠️ **核心规则:所有算法计算必须通过 `_heluo_core.py` 脚本执行,不得手动推理。脚本只管算法;爻辞从 `references/yaoci.json` 读取,卷四行号定位用 `references/juan4_index.json`。**

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
> ⚠️ **核心规则:所有算法计算必须通过 `_heluo_core.py` 脚本执行,不得手动推理。脚本只管算法;爻辞从 `references/yaoci.json` 读取,卷四行号定位用 `references/juan4_index.json`。**

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 170)May include surrounding context.

md
> ⚠️ **核心规则:所有算法计算必须通过 `_heluo_core.py` 脚本执行,不得手动推理。脚本只管算法;爻辞从 `references/yaoci.json` 读取,卷四行号定位用 `references/juan4_index.json`。**

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 171)May include surrounding context.

md
> ⚠️ **核心规则:所有算法计算必须通过 `_heluo_core.py` 脚本执行,不得手动推理。脚本只管算法;爻辞从 `references/yaoci.json` 读取,卷四行号定位用 `references/juan4_index.json`。**

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

md
> ⚠️ **核心规则:所有算法计算必须通过 `_heluo_core.py` 脚本执行,不得手动推理。脚本只管算法;爻辞从 `references/yaoci.json` 读取,卷四行号定位用 `references/juan4_index.json`。**

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

md
> ⚠️ **核心规则:所有算法计算必须通过 `_heluo_core.py` 脚本执行,不得手动推理。脚本只管算法;爻辞从 `references/yaoci.json` 读取,卷四行号定位用 `references/juan4_index.json`。**

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 249)May include surrounding context.

md
> ⚠️ **核心规则:所有算法计算必须通过 `_heluo_core.py` 脚本执行,不得手动推理。脚本只管算法;爻辞从 `references/yaoci.json` 读取,卷四行号定位用 `references/juan4_index.json`。**

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 259)May include surrounding context.

md
> ⚠️ **核心规则:所有算法计算必须通过 `_heluo_core.py` 脚本执行,不得手动推理。脚本只管算法;爻辞从 `references/yaoci.json` 读取,卷四行号定位用 `references/juan4_index.json`。**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description and trigger examples are entirely in Chinese and define the skill's invocation and interaction pattern in that language, but nowhere offer an alternative language or ask the user which language they prefer. Under the policy, a skill that effectively imposes a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs collection of sensitive personal data including full birth date/time, location, gender, and potentially derived identity attributes, but provides no upfront privacy notice, minimization guidance, retention limits, or consent framing. In an agent context, this can lead users to disclose unnecessary personal data without understanding how it will be processed or stored, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document is entirely written as mandatory Chinese-language instructions and does not indicate that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all operational content in a single language and does not indicate that the user can opt into another language or that the skill is intentionally restricted to a Chinese-only audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

At L0872 the section key is 离卦, but its 《象》曰 text and subsequent line texts describe 咸 rather than 离 (for example L0874 says 山上有泽,咸;君子以虚受人。). This is an intent-content divergence inside the skill's reference data and can cause the skill to return the wrong interpretation while claiming to compute heluo/hexagram readings correctly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings and documentation that force a specific language/locale for usage, examples, and outputs. Under the policy, locale constraints should either be optional for the user or clearly justified as region-specific; neither is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The runtime help shown to users is hard-coded in a single language, which is a natural-language policy concern when no language choice is offered. Users who do not read Chinese are forced into that locale with no documented justification in the file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest claims the skill must collect four items: 八字、出生时间、出生地点、性别. But the procedural section asks first for 八字, and if unavailable then asks for birth date/time and location instead, making 八字 an alternative representation rather than an additional required field.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The format rules state that the output must not append any guiding text and should end with the final yearly entry. Later, the document explicitly instructs appending a follow-up message inviting the user to ask about specific years, which directly contradicts the earlier output constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This manifest-style JSON file uses Chinese-only keys and numerals throughout, with no indication that the locale is optional or intentionally region-specific. Under the policy rule, a file that hard-codes a single language without user opt-in or documented justification can be treated as a natural-language locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JSON file consists entirely of Chinese-language natural-language content and provides no indication that the language is optional or user-selectable. Under the policy rule for language/locale constraints, forcing a specific language without user opt-in can be a natural-language policy violation unless clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file is presented as a JSON reference corpus, but the duanyu text at L0343 contains embedded markup-like page annotation (<!-- ============ 原文页码 201-300 ============ -->). That contradicts the apparent intent of maintaining clean structured reference data and suggests the file is acting partly as a source-transcription artifact rather than pure machine-ready JSON content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language instructions and examples entirely in Chinese, which imposes a specific language on users without any visible opt-in or alternative. The policy allows locale constraints when they are explicitly justified, but no such justification appears in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script's runtime messages are fixed to a single language, which can violate language/locale policy when no user choice or documented locale limitation is provided. This is a natural-language policy issue rather than a code-security flaw.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.