天衡命名宗师

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Chinese personal-name helper that asks for birth and family details but shows no code execution, storage, network sharing, or hidden behavior.

Install only if you are comfortable discussing birth date/time and optional family details in chat. Share the minimum needed, avoid parent names unless necessary for conflict checks, and treat the traditional astrology-style analysis as cultural guidance rather than a factual prediction.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger scope is broad enough to match general naming-related queries, which can cause the skill to activate outside its intended domain. Over-broad invocation can misroute users, create confusing or low-quality responses, and increase exposure to unrelated conversations where the skill may solicit unnecessary personal details.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill requires collection of sensitive personal data such as surname, gender, full birth date, and birth time, and optionally family relationship data, without any privacy notice, minimization guidance, or retention/handling explanation. If invoked unnecessarily or used in shared environments, this can expose personal or quasi-identifying information and create privacy and compliance risks.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal