Back to skill

Security audit

反思式塔罗抽取

Security checks for vulnerabilities and agentic risk

Overview

This tarot reflection skill is not clearly malicious, but it asks for broad read, write, and command-execution authority that does not fit its stated purpose.

Review this skill before installing. Its tarot content is mostly coherent and includes useful non-clinical boundaries, but it should not need read, write, exec, API key, callback, file-processing, or command-execution authority. Install only if the publisher narrows the permissions and removes the unrelated automation scope.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The skill declares `read`, `exec`, and `write` capabilities even though its stated purpose is reflective tarot guidance. This creates an unnecessary privilege boundary expansion: if invoked by an agent, the skill could access files or execute commands unrelated to tarot, increasing the risk of data exposure, misuse, or prompt-driven command execution through a misleadingly harmless persona.

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The manifest describes a non-clinical tarot reflection skill, but the description also claims applicability to automation workflows, batch processing, and efficiency optimization. This mismatch can cause an orchestrating agent or user to trust the skill for benign reflection while it is scoped broadly enough to justify operational actions, enabling covert overreach and misuse of the declared powerful tools.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The feature/performance sections claim file parsing, batch processing, API aggregation, command execution, and error handling capabilities that materially exceed a tarot skill’s expected behavior. In context, these claims normalize dangerous system-level actions under an innocuous category, making the capability mismatch more risky because users and agents are less likely to scrutinize it.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The invocation description uses broad language about everyday efficiency and automation rather than a narrow tarot-specific trigger. Ambiguous triggers increase the chance an agent will route unrelated tasks into this skill, where its excessive declared permissions could then be exercised in unintended contexts.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The manifest mixes tarot reflection with generic automation contexts, making the trigger scope unclear. This ambiguity is dangerous here because the skill also advertises privileged tools; an agent may invoke it outside its safe domain and expose local files, shell execution paths, or external callbacks under a misleadingly low-risk label.

Static analysis

No suspicious patterns detected.