Back to skill

Security audit

河洛理数 · 一卦定终身

Security checks across malware telemetry and agentic risk

Overview

This fortune-telling skill is coherent and not malicious, but it requires sensitive birth details and can produce gender-biased personal readings without enough consent or privacy framing.

Review before installing. Use it only if users intentionally want a Heluo-style reading and understand they may be asked for exact birth time, birthplace, and sex/gender. Avoid entering someone else's details without consent, and treat gendered or deterministic predictions as historical fortune-telling text rather than factual advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Confidence
76% confidence
Finding
The trigger conditions are broad enough to activate on generic fortune-telling or horoscope-style requests, which can cause the skill to engage unexpectedly and start soliciting highly sensitive personal details. In this skill's context, overbroad activation increases privacy and consent risk because it may collect birth data, location, and gender before the user clearly understands what is being invoked.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill explicitly directs the agent to collect sensitive personal data including full birth date/time, birthplace, and sex, but provides no upfront privacy notice, purpose limitation, minimization guidance, or consent language. This is especially risky because these fields are unnecessary for many casual informational queries and can be used to profile a person or infer other sensitive attributes.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The referenced text includes explicit sex-specific prescriptions and differential judgments such as distinct outcomes for '女命', which can cause the skill to produce gender-restrictive or discriminatory guidance without user choice or contextual safeguards. In a fortune-telling skill that actively requests sex/gender as an input and uses it to drive life predictions, this is not incidental historical text but operational content that can directly shape outputs and reinforce harmful bias.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
This line is another instance of the dataset assigning different value judgments or role expectations based on sex, without justification or user control. Because the skill's stated behavior is to collect sex and then generate lifelong destiny interpretations, the biased language is likely to be surfaced as personalized advice, increasing the risk of discriminatory and psychologically harmful outputs.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The content around this location also contains sex-specific or gender-restrictive framing that can lead to unequal treatment in generated readings. Within this skill, the danger is amplified because gender is one of the required intake fields and the file is a core prediction reference, so the model may systematically personalize bias rather than merely quote archival text.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.