Back to skill

Security audit

48-zodiac-cyber-reader

Security checks across malware telemetry and agentic risk

Overview

This appears to be a simple remote astrology-style API skill, but users should know birthdates are sent to its server.

Install only if you are comfortable sending birthdate inputs to the skill's remote API. Avoid submitting someone else's birthdate unless you have permission, and do not treat the skill as private unless the publisher documents retention, logging, and sharing practices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The API description explicitly states that birth-date strings are sent to a remote server and resolved server-side, but it does not include a clear user-facing privacy warning or data-handling statement. Birthdates are personal data, and users may not expect them to be transmitted off-platform, creating privacy, consent, and compliance risk if the skill collects or forwards this information without adequate disclosure.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The pairing endpoint accepts two birthdate values, meaning the skill may transmit personal data about two individuals to the remote server without a clear privacy disclosure. This increases the sensitivity of the operation because it can involve third-party personal data, raising consent and privacy concerns beyond a single-user lookup.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.