Back to skill

Security audit

易经占卜-yiJingDivination

Security checks for vulnerabilities and agentic risk

Overview

This divination skill is not malicious, but its broad triggers could route ordinary user messages to an external API, so it needs review before installation.

Install only if you are comfortable with prompts being sent to wenmutang.top. Avoid sharing sensitive personal details, store the API key outside the skill file if your agent supports it, and consider narrowing the trigger patterns before enabling automatic activation.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger patterns include very generic phrases such as '这事…能不能成/行不行' and broad outcome questions like '财运|感情|事业|健康|出行|考试.*怎么样', which can match ordinary conversation that is not actually requesting divination. This can cause the skill to activate unexpectedly, sending unrelated user text to an external API and producing irrelevant or privacy-impacting behavior.

Static analysis

No suspicious patterns detected.