Bazi Calculator - Shunshi AI

Security checks across malware telemetry and agentic risk

Overview

The skill appears to ask for personal birth details for a purpose where that data is expected, with no evidence of hidden persistence, credential use, exfiltration, or destructive behavior.

Before installing, understand that the skill may ask for exact birth details that can identify or profile a person. Use only the precision you are comfortable sharing, avoid entering another person’s data without permission, and prefer skills that clearly state whether this information is stored or sent anywhere.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly requests full birth date, birth time, gender, and birth city, which together form highly sensitive personal data that can enable profiling, identity correlation, or misuse in downstream systems. The skill provides no privacy notice, retention limits, consent language, or minimization guidance, and it further encourages use of exact location/time data for calculation accuracy, increasing sensitivity.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal