Back to skill

Security audit

看相skill

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only physiognomy photo-analysis skill, but it needs Review because it can analyze sensitive personal images through broad photo triggers and make health, personality, career, and fortune inferences without clear opt-in or privacy boundaries.

Install only if you intentionally want physiognomy-style analysis of personal images. Use explicit requests, avoid uploading photos of other people or minors without consent, and do not treat health, personality, career, or fortune outputs as factual medical or life advice. Review the unrelated marketplace capability tags before trusting the listing.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The README states the skill will not predict specific events, yet earlier examples provide concrete time-bounded future guidance such as favorable months and near-term fortune forecasts. This inconsistency can mislead users about the scope and safeguards of the skill, encouraging reliance on deterministic predictive claims despite the stated limitations.

Intent-Code Divergence

Low
Confidence
84% confidence
Finding
The README claims every analysis report includes a disclaimer, but the sample reports omit one. This creates a documentation-to-behavior mismatch that weakens user safety messaging and may cause users to over-trust sensitive personality, health, or fortune-related outputs.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The README says that simply uploading a photo can cause the skill to automatically identify the type and analyze it, which is overly broad for a skill handling sensitive biometric-style personal images. This can lead to unintended invocation and analysis of photos the user did not clearly intend to submit for physiognomy or character inference.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README discusses vision-capable models and API use but does not clearly warn users that uploaded face, hand, or body photos may be sent to an external model provider for analysis. Because these images are highly sensitive personal data, the lack of a clear transmission and privacy notice materially increases privacy and consent risk.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The README says that simply uploading a photo will cause the skill to automatically recognize the image type and perform analysis. Because this skill infers personality, fortune, and health-related traits from biometric-like images, broad auto-triggering can cause sensitive analysis to run without clear user intent or informed consent.

Vague Triggers

Low
Confidence
87% confidence
Finding
The example phrase 'Help me analyze this photo' is very generic and could match ordinary conversation unrelated to physiognomy. In this context, accidental invocation is risky because the skill performs sensitive trait inference from personal images, even if framed as entertainment.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The README does not clearly warn that users are providing highly personal visual data and that the skill derives sensitive inferences about personality, fortune, and health-related characteristics. The existing entertainment disclaimer is not enough to establish informed consent for biometric-like image analysis and pseudoscientific profiling.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to activate on generic photo-analysis requests such as '分析照片' or '帮我看看这张照片', which can route ordinary image requests into physiognomy-based analysis of faces, hands, or bodies. In this context that is risky because the skill processes sensitive biometric-style images and produces character, health, or fate inferences from appearance, increasing the chance of non-consensual sensitive profiling or unexpected handling of user photos.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill introduces face, hand, body, and bone-image analysis without an upfront warning that these are sensitive biometric-style images and that the skill generates highly sensitive inferences about personality, health, aptitude, and life outcomes from appearance. Because the warning appears only later as a lightweight entertainment disclaimer, users may upload personal images without informed consent to the privacy and profiling risks.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The reference content is entirely in Chinese and does not indicate any user language selection, fallback, or translation behavior. In an agent skill, forcing one language can exclude users, cause misinterpretation of outputs, and undermine informed consent—especially here, where the skill performs sensitive physiognomy-style analysis from body-part images and may produce consequential personal inferences.

Static analysis

No suspicious patterns detected.