Back to skill

Security audit

Ziwei Doushu Advisor

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only astrology chart API skill that sends birth details to myfate.ai for its stated purpose, with no hidden executable code or destructive behavior found.

Install only if you are comfortable sending birth date, birth time, gender, and related chart parameters to skill.myfate.ai using your own API key. Review the provider’s privacy and pricing terms before using paid features, and avoid storing exact birth details in long-term memory unless the user explicitly asks for that.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs the agent to send highly sensitive personal data including birth date, birth time, gender, and potentially lunar calendar details to a third-party remote API, but it provides no user-facing privacy disclosure, consent step, retention notice, or data handling limitations. Because these are intimate personal profile attributes and are transmitted off-platform for a non-essential fortune-telling service, the lack of transparent notice and consent materially increases privacy and compliance risk.

Ssd 3

Medium
Confidence
95% confidence
Finding
The instruction to retain prior birth details in memory and automatically reuse them after recharge creates a natural-language data retention risk for highly sensitive personal information. This increases the chance of unintended disclosure across turns, sessions, or to the wrong user context, especially because the retained data is not minimized and concerns intimate personal attributes.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:18