other
- Location
SKILL.md:74- Finding
Excessive External Collection of Personal Data
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 74 and 200–213
Vulnerability Type: Excessive Personal Data Collection
Risk Level: MediumRelevant excerpts:
text Before you start: calling this service sends personal information about the subject — date of birth (plus time, if known), gender, place of birth, current location — to the XinJianXue API (www.xinjianxue.com) for processing; it is used only for this one analysis and is not stored.markdown - There are two input tiers; **both are billed at tier b (basic) — tier a costs no extra tokens**: - **a (full)**: the subject's date and time of birth + gender + place of birth (country + state/region/city) + current location - **b (basic)**: only the subject's date of birth + gender + current location - **Both tiers must provide**: gender, date of birth (if the user knows the time of birth, include it and the call is automatically upgraded to tier a), and the subject's current location (country + state/region/city) - **Tier a additionally requires**: the exact hour + minute of birth, and the place of birth (country + state/region/city) - **Multi-person analysis**: pass a `people` array, each person `{name, birth, gender, place, country}`. - If the user has not supplied everything, the AI must ask for the missing pieces first — never call with parameters missing.Technical Analysis
The Skill requires the agent to collect and transmit date of birth, gender, and current geographic location to an external service before producing a report. It may additionally transmit exact birth time, birthplace, and identifying names for multi-person analysis.
These attributes are linkable personal data and exceed what is inherently necessary to provide ordinary campus relationship advice. The mandatory requirement to ask for missing fields increases collection rather than applying data minimization. The Skill also permits reports about ot ...[truncated 1662 chars]
- Remediation
View remediation
Remediation Suggestions
- Provide a local, advice-only mode that does not call an external API.
- Make external report generation optional rather than a prerequisite for relationship guidance.
- Apply strict data minimization. Do not require exact birth time, birthplace, gender, or current city unless each field has a documented and necessary purpose.
- Prefer coarse location data where location is genuinely required.
- Restrict analysis to the user unless every other data subject provides direct, explicit, and verifiable consent.
- Present a field-by-field disclosure before collection, including purpose, destination, retention period, deletion procedure, legal/controller identity, and a link to the provider's privacy policy.
- Do not claim that the server stores no data unless that guarantee is independently enforceable and auditable.
- Encrypt data in transit, prohibit sensitive values from logs and conversation persistence, and define deletion and incident-response procedures.
- Permit users to omit optional attributes without blocking access to basic relationship advice.
