Back to skill

Security audit

Yijing Oracle Interpretation

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese-language I Ching interpretation skill that generates reflective reports and advice, with no executable code, persistence, credential use, or hidden data access.

Install only if you want a Chinese-language reflective I Ching interpretation aid. Treat outputs as cultural or personal reflection, not professional financial, legal, medical, relationship, or career advice, and verify major decisions through qualified sources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The README and trigger phrases are entirely in Chinese and do not indicate any language selection, fallback, or opt-in behavior. This can exclude or mislead users who operate in other languages, creating accessibility and usability risks, though it does not present a direct code-execution or data-exfiltration threat.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The sales copy promotes automated I Ching interpretation with concrete action suggestions for topics including investment, relationships, and career, but does not clearly warn users not to rely on the output for high-stakes decisions. In this context, the omission can encourage over-trust in advice-like outputs and lead users to make consequential personal or financial choices based on unverifiable spiritual guidance.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill declares several trigger phrases that are broad, conversational expressions such as '帮我看看这个卦' and '得卦了'. These can plausibly appear in ordinary user dialogue and may cause the skill to activate when the user did not explicitly intend to invoke it, leading to context hijacking or unintended routing rather than direct code-execution risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.