Back to skill

Security audit

Huangdaxian Lingqian

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a fortune-telling skill with broad activation phrases, but there is no evidence of hidden access, data collection, persistence, or unsafe actions.

Install only if you want a divination-style assistant. Be aware that broad Chinese phrases about luck, relationships, or career may activate it even when a user intended ordinary advice; this should be adjusted if precise opt-in activation is important.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes broad, high-frequency phrases such as '看看运势', '最近运气', and '问事业' that can match ordinary conversation unrelated to an explicit request to invoke this skill. This can cause unintended activation, leading the agent to steer users into divination-style guidance when they were asking for general advice, which is a scope and consent problem.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The supported question examples include ambiguous prompts like '看看我的姻缘' and '最近事业如何', which are common user utterances that do not clearly indicate a request for this specific skill. In a multi-skill assistant, this increases the chance of accidental routing to fortune-telling behavior instead of neutral informational or advisory handling.

Static analysis

No suspicious patterns detected.