Back to skill

Security audit

liuyao

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Liuyao divination and learning skill with local reference files and helper scripts, and I found no hidden network access, credential use, automatic persistence, or destructive behavior.

Install only if you want a Chinese-style Liuyao divination and learning assistant. Treat readings as cultural or reflective content, not as medical, financial, legal, or major life decision advice; be aware that one optional maintenance script can append quality-check notes inside the skill's own logs directory if manually run.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill is presented as a divination/interpretation capability but includes maintenance behavior that reads local files and persists logs. That hidden operational behavior expands the attack surface and can expose internal content or create unauthorized state changes, especially when users invoke what appears to be a harmless end-user skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a divination/interpretation capability but includes maintenance behavior that reads local files and persists logs. That hidden operational behavior expands the attack surface and can expose internal content or create unauthorized state changes, especially when users invoke what appears to be a harmless end-user skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises executable/script-driven behavior and local file interactions, but does not declare any explicit tool or permission scope. In an agent environment, this can cause overbroad default access, making file reads/writes occur without clear operator review or least-privilege boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions require the assistant to adopt a specific Chinese-speaking persona, including self-reference as "贫道" and addressing the user as "居士," with a fixed opening line. This imposes a language/style constraint without user opt-in, which is a natural-language locale policy concern under the stated rule.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The listed triggers such as "教我学六爻" and especially "帮我起一卦" are presented as direct activation phrases, but the file does not define boundaries, negative examples, or narrow activation context. This can create ambiguity about when the skill should activate versus when a user is making a casual or exploratory mention.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill states that this is an English adaptation and directs users to the Chinese version for fuller references, which imposes a language-specific constraint. The file does not present language selection or user opt-in, so this is a natural-language locale policy issue under the stated rules.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The phrase inviting users to say they want to consult Liuyao about a question is broad and natural-language-like, which can overlap with ordinary conversation and cause unintended skill activation. In agent environments where routing is based on loose semantic matching, this can trigger divination behavior when the user did not explicitly intend to invoke the skill, leading to confusion or policy-bypassing context switches.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The final 'Get Started' instruction uses an underspecified, conversational trigger that does not clearly define scope, exclusions, or invocation boundaries. This increases the chance of accidental activation from ordinary user statements about consulting Liuyao or discussing a question, especially in assistants that auto-select skills from free-form text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown log is entirely written in Chinese and repeatedly describes skill content and optimization goals in a way that suggests a Chinese-only operating mode. Under the policy rule, forcing a specific language without opt-in or documented regional justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents all instructions, templates, and examples exclusively in Chinese, and there is no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. The policy requires flagging language or locale constraints when they are imposed without user opt-in or explicit justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section provides health-related divination about a father's illness improving and gives a time-based prognosis, but it does not clearly warn that the content is not medical advice and should not guide diagnosis or treatment decisions. Users may defer seeking professional care or change treatment behavior based on the prediction, which makes the omission safety-relevant even though the content is framed as divination.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a 六爻占卜 skill focused on generating divination readings and cultural interpretation, but this script performs repository-maintenance behavior by creating a logs directory and appending evolution records to a markdown file. That operational maintenance activity is outside the user-facing divination scope described in the manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code reads SKILL.md and reference/case markdown files, checks for persona slogans and specific philosophical references, counts examples, and generates editorial suggestions. This is a content-governance and documentation-quality workflow, which does not match the manifest's description of a divination skill that supports real/virtual casting and integrates Confucian/Taoist philosophy for readings.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The quality checks require specific Chinese-language cultural references and persona markers such as '贫道' and '居士', effectively enforcing one linguistic and stylistic locale. This is a natural-language policy issue because the script does not offer user opt-in or any documented justification for restricting outputs to that language/style.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents all instructions and content in a single language with no visible opt-in, alternative language option, or justification that the skill is region-specific. Under the policy, forcing a specific language without user choice can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all instructional and descriptive content in a single language, which can be a natural-language locale policy issue when no user opt-in or justification is provided. The file does not indicate that the skill is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all instructions and reference material exclusively in Chinese, with no note that the skill is Chinese-only or that users can choose another language. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, and there is no indication that the user can choose another language or that the locale restriction is intentional. Under the policy rule for language or locale constraints, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all instructional content in Chinese and does not indicate that users can choose another language. Under the policy rule for language or locale constraints, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module docstring and user-facing prompts indicate the skill is intended to operate entirely in Chinese. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The docstring says the function converts coin-toss results to 'binary', which suggests a straightforward binary encoding. In practice, it maps each three-coin result to a three-character pattern representing line types such as old/young yin-yang states, so the documentation is misleading about what the function actually returns.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI instructions and validation logic require users to enter specific Chinese strings such as "正正反" and provide no language choice or opt-in. This enforces a locale-specific interaction model without documenting the restriction or offering alternatives.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language strings and documentation in a single enforced language, including the module description and later console output, but does not provide any opt-in or alternative locale handling. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.