Back to skill

Security audit

八字操作系统V2.0

Security checks for vulnerabilities and agentic risk

Overview

This is not malware, but it collects sensitive birth details, saves named personal reports, and gives under-bounded gendered, relationship, and health guidance.

Install only if you are comfortable sharing precise birth data and possibly a name with the agent, and treat the generated report as cultural or entertainment content rather than medical, financial, relationship, or life-planning advice. Avoid saving reports with real names, keep the output folder private, and do not rely on its gendered or health claims for consequential decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (29)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill makes a deterministic negative claim tied to women: '女命伤官旺 → 必然克正官 → 婚姻不顺为大概率.' This can produce stigmatizing and self-reinforcing advice about a user's relationships based solely on gendered metaphysical categorization, which is especially harmful in a personalized counseling-style context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill makes a deterministic negative claim tied to men: '男命劫财旺 → 克财夺财 → 克妻损财为大概率.' This encodes harmful sex-based stereotypes into personalized analysis and may influence users' financial or relationship decisions through unjustified, discriminatory assertions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The README presents the skill entirely as a Chinese-language system and frames its operating model and outputs in Chinese, but does not mention any ability for the user to choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README instructs users to enter sensitive personal data including birth date, time, place, and sex, and states that reports are written to an output directory, but it does not disclose retention, local storage, sharing, or handling risks. This creates a real privacy and data-protection issue because users may unknowingly provide identifying data that can be stored in plaintext and exposed through backups, syncing, repo sharing, or other tooling around the vault.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description is written as a fixed Chinese-language skill and does not indicate that language can be adapted based on user preference. While not a direct security flaw, fixed locale behavior can reduce informed consent and comprehension of privacy-sensitive actions, especially when the skill collects personal data and generates files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly collects highly sensitive personal data including birth date, precise birth time, birthplace, and sex, then uses it for analysis without any user-facing privacy warning or data-handling notice. Even if intended for astrology, these attributes are personal and can increase privacy risk, especially when combined and retained in generated files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly invites users to submit birth information for full life analysis, which is sensitive personal data and can also reveal inferred traits about identity, beliefs, relationships, and life circumstances. There is no privacy notice, data-handling disclosure, or minimization guidance, which increases the risk of overcollection, inappropriate retention, or users sharing more personal data than necessary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill encodes a rigid gender-specific interpretation rule for relationship analysis without user choice or contextualization. In a system that generates personalized assessments, this can produce discriminatory or inaccurate outputs for users who do not fit binary assumptions, causing exclusion, misclassification, and potentially harmful advice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document explicitly encourages users to treat some astrological outputs as sufficiently reliable to 'directly conclude' at 90%+ confidence and to make clear judgments at 80–90%, while only framing the percentages as methodological estimates. It does not provide a strong user-facing safety warning that such outputs are not evidence-based and should not be used for consequential decisions, which can overstate trustworthiness in domains like health, relationships, and life planning.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The framework hard-codes sex-based interpretive rules as mandatory (e.g., '男女命十神本质不同' and '不可混用') without offering user choice, caveats, or a non-gendered mode. In a system that produces personalized guidance, this can operationalize discriminatory profiling and lead to biased or exclusionary outputs, especially for users who are nonbinary, transgender, or do not consent to gender-essentialist analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This section explicitly states that male/female interpretive differences are '本质不同' and '绝对不可混用,' making gender essentialism a mandatory operating rule. Because the skill is designed to analyze people and relationships, this increases the likelihood of discriminatory outputs and denies user autonomy over whether gendered assumptions should be applied.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The content maps missing five elements to specific physical conditions such as respiratory, liver, kidney, cardiovascular, and digestive concerns without any disclaimer that this is not medical advice. Users may treat these claims as health guidance and delay appropriate evaluation or care, especially because the skill presents itself as a systematic diagnostic framework.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file explicitly recommends using five-element energy analysis to '看健康' by inferring which organs need attention from the weakest element, again without any warning or limitation notice. In a skill that automates end-to-end fate analysis, this can be perceived as actionable health assessment and may encourage unsafe self-diagnosis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document makes deterministic claims about marriage, parents, children, health, career, and late-life outcomes based solely on birth-chart patterns, without uncertainty, consent framing, or user agency. In this skill context, those statements are operational content rather than abstract folklore, so they can unduly influence vulnerable users' decisions and reinforce harmful self-judgments or relationship conclusions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The content presents gender-linked personality and role assumptions (for example, fixed distinctions for 男命/女命 and traits like 刚/柔) as default analytical rules without qualification or user choice. In a system that generates personalized guidance, this can reinforce harmful stereotypes, exclude non-binary or transgender users, and lead to biased or alienating outputs that users may treat as authoritative.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The text assigns gender-specific negative outcomes as fixed rules (e.g., '男命尤忌' and '女命尤忌') without qualification, uncertainty, or consent. In a predictive divination skill, this can reinforce discriminatory stereotypes and may influence users' relationship or self-worth decisions based on gendered claims presented as authoritative guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

These lines continue gender-specific normative assertions, including rule variations based on sex and statements like '男忌酒色女小心产厄,' presented as direct guidance. Because the skill claims expert, systematized analysis, users may over-trust these claims and make personal, health, or relationship decisions from biased and unqualified gendered predictions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The content encodes fixed gender-specific matchmaking rules such as '男命/女命' and ties recommendations to sex without offering alternatives, caveats, or user choice. In a user-facing agent, this can lead to exclusionary or discriminatory guidance, especially for users who are non-binary, same-sex couples, or whose preferences do not fit the assumed framework.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document explicitly prioritizes bride/groom roles using fixed sex-based assumptions, including '以新娘为主' and references to male/female-specific weighting. This creates a biased decision framework that can systematically mis-handle users outside those assumptions and may produce unfair or alienating outputs in an automated system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The content hard-codes binary, gender-specific relationship rules ('男命' and '女命') and assigns different romantic meanings based solely on sexed categories without user choice, context, or qualification. In a guidance-oriented skill, this can produce exclusionary or misleading advice for users who are non-binary, same-sex attracted, or simply do not fit the framework, and may lead the agent to present discriminatory outputs as authoritative.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Phrases such as '克夫', '克妻', and similar deterministic negative labels attach harm, blame, or defectiveness to gendered partner roles without qualification. Because the skill is designed to deliver personal life advice, these labels can stigmatize users or their partners, reinforce harmful stereotypes, and encourage emotionally damaging conclusions about relationships.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file gives concrete health-risk interpretations and behavior suggestions based on fortune-telling signals, but it does not place an immediate, prominent instruction in that section to consult a qualified clinician before acting. Although the document elsewhere says '医学优先' and discourages death prediction, users may still treat these mappings as actionable medical triage and delay proper diagnosis or self-manage incorrectly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to write a report to an output directory using the person's name in the filename, but does not warn the user that personal data and derived sensitive inferences will be persisted. This can unintentionally expose private information to other users, tools, backups, or repository history depending on the environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file is entirely written in Chinese and provides no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations in natural-language content. This markdown file presents all instructional content in a single forced language, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-only regional context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.