Bazi Qimen

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This is a local astrology-style chart calculation skill with some overly broad activation wording but no evidence of hidden access, persistence, network use, or destructive behavior.

Install this only if you want Bazi and Qi Men Dun Jia cultural/metaphysics calculations. Be aware it may trigger on broad words like chart, pattern, or interpretation, and treat any career, health, relationship, or finance discussion as non-professional reference material rather than advice.

SkillSpector (2)

By NVIDIA

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes generic terms such as "interpretation," "pattern," and "chart calculation," which are common across many unrelated domains. In an agent-routing context, this can cause unintended invocation of the skill for off-topic requests, leading to irrelevant analysis, user confusion, or accidental exposure to tool execution paths the user did not intend to use.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill instructs the agent to default to Bazi calculation, then supplement with Qi Men, when user intent is unclear. This ambiguous fallback can cause the system to perform substantial unsolicited analysis and potentially run scripts without sufficiently confirming the user's actual request, increasing the risk of misrouting and unnecessary tool use.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal