Back to skill

Security audit

​​bazi-engine(四柱八字命理引擎)​

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly an offline Bazi fortune-telling tool, but it includes under-disclosed sensitive-photo, health/lifespan, and unrelated monitoring material that should be reviewed before installation.

Install only if you are comfortable sharing birth details with the agent session. Use a pseudonym instead of a real name, do not provide face or palm photos unless you explicitly want that separate analysis, and do not treat health, lifespan, financial, legal, or relationship predictions as factual advice. Do not run tools/monitor_usage.js unless you intend to use a GitHub token and local fingerprint file for publisher-side monitoring.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding
The skill is presented as a user-facing Bazi analysis assistant, but the bundled behavior described in the documentation includes a much broader toolchain: rule generation, file patching, E2E automation, external monitoring, and build/test utilities. That mismatch can mislead reviewers and users about the operational scope, making it easier for non-essential or sensitive behaviors to be shipped under a benign-looking skill identity.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Including a code-search/API-based usage monitoring capability inside documentation for a fortune-telling skill introduces unrelated surveillance functionality. If exposed in the deployed environment, it could trigger outbound queries using local secrets such as API tokens and perform monitoring that users would not reasonably expect from this skill.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
A manifest advertising Bazi analysis while bundling instructions for GitHub/Baidu/Bing surveillance creates scope creep beyond the stated purpose. This is dangerous because broad, unrelated network behaviors can evade least-privilege review and may normalize external data transfer in a skill that primarily handles sensitive personal birth data.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The rule database materially expands the skill from fortune analysis into health profiling, including symptom and organ-related claims tied to user birth data. In this skill context, that is risky because users may treat generated health inferences as personalized medical guidance, especially when the system presents them as structured, authoritative, and sourced from classical texts.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The prompt materially expands the skill beyond the stated Bazi scope into Ziwei, face reading, palm reading, and other divination systems. This creates scope drift that can cause the agent to collect additional sensitive inputs and make unsupported inferences users did not reasonably consent to when invoking a Bazi-focused skill.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The template instructs the agent to request facial and palm photos, which are sensitive biometric-style inputs not described in the skill metadata. Collecting such images unnecessarily increases privacy risk and broadens the attack surface for profiling, retention, and secondary use of highly sensitive personal data.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
Embedding physiognomy and palmistry in a Bazi skill introduces unjustified sensitive-trait inference from appearance and body features. Even if framed as divination, this can normalize collection and interpretation of biometric-adjacent data with little necessity for the declared service.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The document claims a professional boundary against medical domains, but elsewhere directs the model to infer health conditions and related risks from astrology, face reading, and palm lines. This contradiction can mislead users into treating non-evidence-based outputs as health guidance, potentially delaying appropriate professional care.

Intent-Code Divergence

Low
Confidence
90% confidence
Finding
Although the policy says not to predict death, the palmistry section explicitly links the life line to lifespan, inviting lifespan-style prediction by implication. This inconsistency weakens safeguards and can lead to harmful mortality-related claims despite the stated prohibition.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The README instructs users to provide highly sensitive personal data including name, full birth date and time, gender, and birthplace, but does not pair that request with any clear privacy notice, data-handling explanation, retention policy, or minimization guidance. In a skill context, this is risky because these fields can be used for identity correlation, profiling, or reidentification, especially when combined together.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly asks users for highly sensitive personal data including full name, date of birth, exact birth time, sex, and birthplace, but the README does not provide any meaningful privacy notice, retention policy, minimization guidance, or handling constraints at the point of collection. In an agent/skill context, these data points are sufficient for identity profiling and can be misused for tracking, re-identification, or secondary use beyond the stated purpose, especially because birth details are durable personal identifiers.

Vague Triggers

High
Confidence
89% confidence
Finding
The activation rule is broad enough to auto-trigger on generic terms like '算命' or '八字' even when the user has not clearly opted into this skill. In context, the skill then solicits highly sensitive personal information including name, birth date, time, sex, and birthplace, so over-triggering raises privacy and consent risks.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The file content is entirely in Chinese and encodes domain rules in a single locale without any visible mechanism for user language preference or fallback. In a skill that may be invoked implicitly, this can cause the agent to respond in an unintended language, reducing user comprehension and informed consent, though it is not a direct code-execution or data-exfiltration issue.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This section instructs the agent to make severe predictions about early death, disability, imprisonment, and major life crises, and even labels some patterns as 'highest-level danger signals' based on anecdotal case validation. In a fortune-telling skill that solicits personal birth data and presents outputs as authoritative and traceable, this can plausibly cause psychological harm, unsafe decisions, delayed real-world care, or coercive advice escalation, especially because there is no warning that such claims are not reliable or should not guide health or safety decisions.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This content gives health, disease, longevity, and disaster judgments based on fortune-telling rules, including references to illness, death, surgery, accidents, and fate outcomes, without any safety framing or disclaimer. In the context of an interactive bazi skill that solicits personal data and is meant to provide personalized guidance, users may treat these outputs as actionable medical or life advice, causing psychological harm, delayed care, or harmful decisions.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The text encodes gender-essentialist and prescriptive norms such as defining women primarily through husbands and children, assigning fixed moral traits and life outcomes by gender, and labeling people with stigmatizing judgments. In this skill context, those rules are likely to be surfaced as personalized readings, which can produce discriminatory, demeaning, or manipulative outputs presented as authoritative analysis.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The document’s usage instructions explicitly direct collection of birth date, birth time, and related profiling inputs for fortune-telling, but do not include any warning about sensitivity, minimization, consent, or safe handling. In this skill’s context, those fields can be combined with name, gender, and birthplace from the broader skill metadata to create highly sensitive personal profiles, increasing privacy and misuse risk.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This content makes health, disease, and lifespan judgments from birth data without any warning that such claims are unverified and should not be used for medical or safety decisions. In this skill’s context, the material is likely to be operationalized into personalized advice, which increases the risk of users delaying care, worsening anxiety, or making harmful life decisions based on pseudoscientific predictions.

Missing User Warnings

Low
Confidence
91% confidence
Finding
The file includes relationship, marriage, family, and child-related judgments without warning that these claims are speculative and may negatively influence personal decisions. Because the skill is explicitly intended for fortune-telling and compatibility-style use, users may over-rely on these outputs when making high-stakes choices about partners, marriage, or family relationships.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The document gives health, lifespan, and misfortune judgments in a deterministic style without an explicit safety warning, reliability disclaimer, or instruction to avoid medical decision-making. In the context of an agent skill that collects personal birth data and performs personalized analysis, this can lead users to act on harmful pseudo-medical or fatalistic advice, especially around health and longevity.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill requests face and palm photos without a clear user-facing privacy warning covering collection, use, storage, sharing, and deletion of sensitive image data. Because these images may reveal biometric characteristics, the absence of explicit notice and minimization controls significantly raises privacy and compliance risk.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
Forcing Chinese output without user choice is primarily a usability and consent issue rather than a direct security flaw, but it can impair comprehension of disclosures, warnings, and limitations for non-Chinese-speaking users. In a skill that requests personal data and gives sensitive life guidance, reduced comprehension increases downstream risk.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill is configured to auto-activate on very broad trigger phrases such as "算命" or "八字," and explicitly says it should be invoked even when the user did not ask to use the skill. That creates an overreach risk where sensitive personal-data collection and spiritually/medically adjacent advice may begin without clear user intent, increasing the chance of privacy intrusion, unwanted profiling, and accidental activation in ordinary conversation.

Natural-Language Policy Violations

Medium
Confidence
77% confidence
Finding
The skill content is written as if operation will occur in Chinese only, without offering a user language choice or clearly documenting that restriction in a user-facing way. This can cause consent and comprehension problems: users may provide sensitive birth details without fully understanding prompts, caveats, or disclaimers, which is especially risky for a skill that collects personal information and provides consequential-sounding analysis.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The script captures screenshots after filling forms with personal data such as name, birth date, birth time, gender, and birthplace. Even though the sample values are hardcoded test data here, this pattern is privacy-sensitive because screenshots can expose personal or quasi-identifying information and may later be reused with real user data in local runs, CI artifacts, or shared debugging bundles.

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.env_credential_access

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tools/audit_hit_distribution.js:30

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tools/check_conflicts.js:6

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tools/check_dup_hits.js:6

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tools/test_dst.js:20

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tools/test_eval_state.js:10

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tools/test_liuri_v2.js:7

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tools/test_liuyue_v2.js:7

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tools/test_p1_fixes.js:8

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tools/test_ui.js:10

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tools/test_xiyong.js:17

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tools/verify_edu_rules.js:19

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tools/verify_sleep_rules.js:18

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tools/verify_ux_e2e.js:19

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
tools/monitor_usage.js:47