Back to skill

Security audit

Xiaoliuren skills

Security checks across malware telemetry and agentic risk

Overview

This is a coherent text-only Xiaoliu Ren divination skill, with no hidden code or data access, but users should not rely on its health or other high-stakes readings for real decisions.

Install only if you want an agent to answer Xiaoliu Ren divination requests. Prefer explicit invocation if your agent supports it, and do not use the skill's health, legal, financial, or safety-related readings as a substitute for qualified professional advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The README states that the skill will be automatically loaded whenever the user generally describes a divination request, which is a broad trigger tied to natural-language intent rather than a narrowly scoped command. In agent ecosystems, this can cause unexpected activation, prompt-surface expansion, and misrouting of unrelated requests that mention fortune-telling terms, increasing the chance of unintended behavior or prompt injection exposure through the loaded skill.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The Hermes section describes automatic loading based on a user's divination request but does not define precise trigger boundaries or exclusions. Ambiguous auto-load conditions are risky because they let the hosting agent interpret broad intent heuristically, which can lead to over-activation and unnecessary exposure of skill instructions in contexts the user did not explicitly intend.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The integration guidance for other agents claims the skill will automatically invoke when users request Xiaoliu Ren divination, but it does so without platform-specific safeguards or trigger specificity. This creates a reusable pattern of broad intent matching across multiple agent environments, making accidental activation and prompt-scope expansion more likely wherever the skill is deployed.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill gives health-related divination interpretations such as illness severity, prognosis, and recovery outcomes, but only places a general 'for reference' disclaimer at the end of the template rather than a clear upfront warning not to use the output for medical decisions. This can cause users to delay, avoid, or substitute proper medical care based on occult output, especially because the content presents itself as authoritative and 'verified'.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.