Back to skill

Security audit

Chinese Name Generator - Cantian AI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local Chinese naming helper with some overstated marketing, but I found no hidden data access, persistence, or destructive behavior.

Install only if you are comfortable with a skill that mainly automates Chinese-character name scoring, not the full range of broader naming scenarios in its description. Prefer Node 24 so you can avoid the optional unpinned tsx install; if you need tsx, pin and review the dependency first.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:35
Finding

Unpinned Third-Party Runtime Tool Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:35
Vulnerability Type: Unpinned npm dependency and mutable supply-chain resolution
Risk Level: Medium

bash
npm i -D tsx

Technical Analysis

The installation instructions retrieve tsx without specifying an exact version. The project also contains no lockfile, and package.json does not declare a reviewed version of tsx. The installed package and its transitive dependencies are therefore resolved from the configured npm registry at installation time and can differ from the components available when the Skill was audited.

npm installation may execute package lifecycle scripts. If the resolved tsx package, one of its transitive dependencies, the package maintainer account, or the configured registry is compromised, attacker-controlled code could run during installation or when tsx is subsequently used to execute the TypeScript scripts.

This finding concerns the dependency installation process. No malicious execution, network access, persistence mechanism, or credential access was identified in the checked-in project scripts.

Attack Path

  1. An attacker compromises the selected npm package release, a transitive dependency, a maintainer account, or the npm registry configured on the target system.
  2. A user follows the documented compatibility instructions and runs npm i -D tsx.
  3. npm resolves and downloads the currently available package graph because neither an exact dependency version nor a lockfile constrains resolution.
  4. Malicious lifecycle code may execute during installation, or malicious package code may execute when the user invokes the installed tsx runtime.
  5. The payload runs under the account and environment used for installation or script execution.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user running npm or tsx. The potential scope includes files ...[truncated 279 chars]

Remediation
View remediation

Remediation Suggestions

  1. Declare tsx in package.json using a reviewed exact version rather than installing the latest available release.
  2. Generate and commit a lockfile that records the complete dependency graph and integrity hashes.
  3. Replace the unconstrained installation instruction with npm ci, which installs the dependency versions recorded in the lockfile.
  4. Regularly review and update dependencies through a controlled process that includes vulnerability scanning and integrity verification.
  5. Prefer direct execution with the supported Node.js runtime when available, avoiding the optional third-party runtime entirely.
  6. If package lifecycle scripts are not required, consider installing with npm ci --ignore-scripts after verifying that this does not break legitimate functionality.
  7. Advise users not to run dependency installation with administrator or root privileges.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (46)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code’s real function is narrowly scoped: analyze one supplied Chinese name via local Hanzi records, San Cai/Wu Ge calculations, favorable-element matching, and simple scoring. The declared description promises a much broader naming assistant that can recommend, generate, compare, and rename across many domains (personal, corporate, brand, bilingual, pet, etc.). Those generation/comparison capabilities are absent. There is overlap on Chinese name analysis and favorable-element consideration, but the implemented behavior is materially narrower and differently centered than the declared purpose, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code is clearly related to Chinese naming, so this is not a total-purpose mismatch. However, the declared description substantially overstates the implemented capabilities. The script is a narrow offline generator/ranker for Chinese given names based on Hanzi metadata, five-element filtering, and WuGe/Sancai scoring. It accepts surname, desired name length, favorable/secondary element, and a few filter toggles; then it enumerates one- and two-character combinations, scores them, and prints results. There is no functionality for English/bilingual naming, semantic/pronunciation evaluation beyond excluding obviously unsuitable particles/interjections, candidate comparison workflows, rename advice, company/brand/industry positioning, user-targeted audience alignment, pet/stage/web names, or BaZi computation from birth data. Also, despite the description framing favorable elements as primary and WuGe as secondary, the implementation gives substantial explicit scoring to all five WuGe numbers and inter-element relations, making numerology a core mechanism rather than merely secondary. Therefore the declared purpose does not accurately represent the actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code’s primary purpose is a narrow favorable-element-based Chinese given-name candidate generator. It does align with one slice of the description—Chinese name recommendation prioritizing 喜用神/五行—but the declared description substantially overstates the implemented functionality. There is no logic for gender, zodiac, semantic analysis, phonetic smoothness beyond excluding some obvious non-name pinyin, surname-aware matching, BaZi derivation, company/brand/English naming, rename reasoning, or candidate comparison. WuGe is specifically said to be secondary, but this script explicitly says 'no WuGe scoring' and only includes stroke-count fields in output. Because the actual implementation is materially narrower than the declared multi-scenario naming-analysis skill, this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
- 执行目录:在 skill 根目录(`SKILL.md` 所在目录)运行以下命令

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
- `scripts/analyzeName.ts`:分析指定姓名的三才五格结果

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
- `scripts/analyzeName.ts`:分析指定姓名的三才五格结果

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
- `scripts/analyzeName.ts`:分析指定姓名的三才五格结果

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
- `scripts/analyzeName.ts`:分析指定姓名的三才五格结果

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

md
- `scripts/analyzeName.ts`:分析指定姓名的三才五格结果

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
- `scripts/analyzeName.ts`:分析指定姓名的三才五格结果

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

md
- `scripts/analyzeName.ts`:分析指定姓名的三才五格结果

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 192)May include surrounding context.

md
- `scripts/analyzeName.ts`:分析指定姓名的三才五格结果

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
- `scripts/analyzeName.ts`:分析指定姓名的三才五格结果

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 246)May include surrounding context.

md
- `scripts/analyzeName.ts`:分析指定姓名的三才五格结果

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 247)May include surrounding context.

md
- `scripts/analyzeName.ts`:分析指定姓名的三才五格结果

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 253)May include surrounding context.

md
- `scripts/analyzeName.ts`:分析指定姓名的三才五格结果

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- `scripts/pickName.ts`:按喜用神筛选候选名字;有姓氏时附加三才五格评估(单字/双字)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
- `scripts/pickName.ts`:按喜用神筛选候选名字;有姓氏时附加三才五格评估(单字/双字)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
- `scripts/pickName.ts`:按喜用神筛选候选名字;有姓氏时附加三才五格评估(单字/双字)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
- `scripts/pickName.ts`:按喜用神筛选候选名字;有姓氏时附加三才五格评估(单字/双字)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

md
- `scripts/pickName.ts`:按喜用神筛选候选名字;有姓氏时附加三才五格评估(单字/双字)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

md
- `scripts/pickName.ts`:按喜用神筛选候选名字;有姓氏时附加三才五格评估(单字/双字)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 210)May include surrounding context.

md
- `scripts/pickName.ts`:按喜用神筛选候选名字;有姓氏时附加三才五格评估(单字/双字)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 219)May include surrounding context.

md
- `scripts/pickName.ts`:按喜用神筛选候选名字;有姓氏时附加三才五格评估(单字/双字)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 247)May include surrounding context.

md
- `scripts/pickName.ts`:按喜用神筛选候选名字;有姓氏时附加三才五格评估(单字/双字)

Static analysis

No suspicious patterns detected.