Back to skill

Security audit

bazi-fortune-telling

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese-language traditional Bazi fortune-telling guide with no code execution, network access, persistence, or hidden data handling.

Before installing, understand that the skill is written in Chinese and is for traditional cultural fortune-telling. It may use sensitive personal birth details for user-requested interpretations, and its outputs should not be used as a substitute for professional medical, legal, financial, or mental-health advice.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The manifest description is entirely written as an instruction set in Chinese and frames the skill's usage, triggers, and behavior only in that language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
This markdown file presents all instructions and examples only in Chinese, and there is no natural-language indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the stated policy, forcing a specific language without user opt-in is a locale/language policy concern.

Static analysis

No suspicious patterns detected.