Back to skill

Security audit

韦特塔罗占卜免费版

Security checks for vulnerabilities and agentic risk

Overview

This tarot skill is not clearly malicious, but it requests file and command powers and includes vague save/export behavior that is broader than a conversational tarot reading needs.

Review this skill before installing. Prefer a version that removes exec and write access, uses only tarot-specific instructions, and clearly states that readings are not saved unless you explicitly choose a known destination.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The documentation is internally inconsistent: it says the free version does not persist divination records, yet elsewhere advertises save/export/import/reset style behaviors. In a skill that also declares file and execution capabilities, this ambiguity can mislead users and the hosting agent into handling user content in ways the user did not expect, increasing the risk of unintended local storage or data exposure.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The quick-start promises that no command-line interaction is needed, but the skill declares exec capability and later documents command/network-diagnostic behavior. This mismatch hides the actual power of the skill and can cause an agent to grant or invoke command execution for a tarot workflow that should be purely conversational.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
A tarot-reading skill has no legitimate need for broad read, write, and exec capabilities to perform card draws and text interpretation. Granting these powers unnecessarily expands the attack surface, enabling filesystem access or command execution if the skill is triggered or adapted in unintended ways.

Context-Inappropriate Capability

High
Confidence
94% confidence
Finding
The documented create/modify/delete/import/export operational modes are far broader than the stated purpose of a lightweight tarot assistant. In the presence of file and execution privileges, these generic verbs resemble a scaffold for arbitrary system actions rather than a bounded divination feature, making misuse or overreach more likely.

Vague Triggers

Low
Confidence
76% confidence
Finding
The workflow tells the assistant to ask about saving a record without clearly defining whether saving is supported, what gets saved, or how the action is invoked. In a skill with write capability, this ambiguity can lead to unintended persistence of sensitive personal reflections or relationship/career questions.

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The skill mentions save/export-style operations but provides no warning about where data may go, what system effects occur, or what permissions are being exercised. Because tarot inputs may contain intimate personal data, undocumented handling of export or save actions creates privacy and local data exposure risks.

Static analysis

No suspicious patterns detected.