Back to skill

Security audit

BaZi Chart Calculator (八字排盘)

Security checks for vulnerabilities and agentic risk

Overview

This is a local BaZi astrology calculator whose requested inputs and code behavior match its stated purpose, with install and privacy caveats.

Install only in an isolated virtual environment, avoid running pip as an administrator, and share birth details only when you intentionally want a BaZi chart calculated. For stronger supply-chain assurance, pin and hash-lock the ephem dependency before installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:1
Finding

Unpinned and Unhashed Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: scripts/requirements.txt:1
Related Installation Instructions: SKILL.md:14-15
Vulnerability Type: Supply-chain risk caused by non-reproducible dependency resolution
Risk Level: Medium

Vulnerable Code

scripts/requirements.txt:1:

text
ephem>=4.1.0

SKILL.md:14-15:

bash
python3 -m venv venv && source venv/bin/activate
pip install -r scripts/requirements.txt

Technical Analysis

The dependency specification uses only a lower-bound constraint. As a result, installation can resolve to any currently available or future version of ephem that satisfies >=4.1.0. The project also provides no package hashes or lock file to verify the integrity and exact identity of the installed artifact.

Python package installation may execute package-controlled build or installation logic. Consequently, the effective code installed by following the documented setup procedure can differ from the code reviewed during this audit.

This is a supply-chain hardening weakness rather than evidence that ephem, the package index, or the project is currently malicious. Exploitation requires compromise of the dependency's publishing channel, a malicious future release, or control of the package index used by the victim.

Attack Path

  1. An attacker compromises the dependency publisher, distribution channel, or package index configured in the victim's environment.
  2. The attacker publishes a malicious ephem release whose version satisfies >=4.1.0.
  3. A user follows the documented setup instructions.
  4. pip resolves the unconstrained dependency to the malicious release.
  5. Package-controlled build, installation, or runtime code executes with the privileges of the user running pip or the BaZi application.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the installing or application user. Depending on that user's permissions, this ...[truncated 472 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the lower-bound constraint with an exact version that has been reviewed and tested:
text
ephem==<reviewed-version>
  1. Generate a hash-locked dependency file and require hash validation during installation:
bash
pip install --require-hashes -r scripts/requirements.txt
  1. Record hashes for every permitted distribution and platform artifact, or use a lock-generation tool that produces a reproducible requirements file.

  2. Install packages only from an explicitly configured, trusted package index. Where appropriate, use an internally controlled package mirror containing approved artifacts.

  3. Add automated dependency scanning and controlled update review. Dependency upgrades should be tested and audited before updating the pinned version and hashes.

  4. Perform installation and execution as an unprivileged user inside an isolated virtual environment or container. Do not run the documented installation command with administrative privileges.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (15)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to extract and process birth date, time, city, and gender from conversation, which together constitute sensitive personal data and can support profiling or re-identification. Because the skill provides no privacy notice, consent step, minimization guidance, or retention boundary, users may unknowingly disclose highly sensitive birth information for astrology processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This file contains natural-language strings specifying that the gender input must be "male" or "female" only. That is a policy-relevant language constraint presented without any opt-in, alternative handling, or justification, which can exclude users outside that binary choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The function's contract says it returns a UTC datetime, but the implementation manually subtracts 8 hours from a value already treated as UTC. That creates a systematic time-shift error that can propagate into all downstream solar-term, month-pillar, and luck-cycle calculations, producing incorrect chart outputs in a way that is hard to detect.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

get_jieqi_moment promises Beijing time, but it converts a value that was already incorrectly shifted by 8 hours, causing the final CST result to be wrong as well. In this skill's context, precise solar-term boundaries directly determine month classification and adjacent-term calculations, so a fixed offset bug can materially alter astrological results for users born near boundary times.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code includes a natural-language and interface constraint that requires users to identify as either "male" or "female" via the choices list. Under the policy, forcing a specific user classification without opt-in or justification is a natural-language policy concern applicable to all file types.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JSON dataset uses Chinese-only city identifiers throughout, including entries such as 北京 and 上海, with no indication of multilingual support or a documented region-specific constraint. Under the policy rule for natural-language violations, forcing a specific language or locale without user choice can be a compliance issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code file contains user-facing natural-language documentation entirely in Chinese, including the module description and function docstrings. Per the policy, forcing a specific language without opt-in or a documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code file uses Chinese-language docstrings and comments throughout, which can reflect a fixed language assumption in the skill's natural-language surface. The file does not indicate that Chinese is optional, user-selected, or justified as a region-specific constraint, so it may violate the language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This file contains natural-language documentation entirely in Chinese in the module docstring and function docstrings. Under the policy rule for language or locale violations, this can be considered forcing a specific language without user opt-in because no alternative language option or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file's natural-language documentation is entirely in Chinese, and there is no indication that users or maintainers can choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This Python file is a code file, so only SQP-2 and SQP-3 apply. The natural-language strings and documentation are entirely in Chinese, which imposes a specific language/locale without any visible opt-in or justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code file contains natural-language documentation exclusively in Chinese, including the module description and explanatory comments, with no indication that the skill is region-specific or that users may choose another language. Under the policy rule for language or locale constraints, this is a natural-language policy issue because it imposes a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language descriptions and function documentation are entirely in Chinese, which imposes a specific language on users and maintainers without any opt-in or stated regional justification. Under the policy, language constraints should either offer choice or be clearly documented as intentionally locale-specific.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
86% confidence
Finding

The dependency is specified with a lower bound only (ephem>=4.1.0), which allows future versions to be installed without review. This can introduce supply-chain risk through breaking changes or a compromised upstream release, reducing build reproducibility and making security posture harder to control.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
ephem>=4.1.0

Static analysis

No suspicious patterns detected.