Back to skill

Security audit

八字操作系统

Security checks across malware telemetry and agentic risk

Overview

This is a coherent BaZi astrology skill, but it saves named reports and makes sensitive health, relationship, fertility, family, and past-event inferences from birth data without clear privacy controls.

Only install if you are comfortable entering birth date, exact time, birthplace, gender, and possibly a name into this workflow, and having a local Markdown report saved. Use a pseudonym, review or disable report saving if possible, delete outputs you do not want retained, and do not rely on the health, fertility, relationship, or life-decision predictions as factual or professional advice. If using the source with Claude Code directly, review the local settings permissions before enabling Git or WebSearch access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (27)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill is granted Git repository initialization, add, and commit permissions even though its stated purpose is BaZi analysis, not software development or version control. These capabilities can be used to create or modify repositories, stage arbitrary files, and persist potentially sensitive content into commit history, which expands the blast radius well beyond the skill’s functional need.

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
Granting unrestricted WebSearch to a skill focused on local BaZi charting and analysis is broader than necessary and enables unbounded outbound data access. In practice, this can be abused to exfiltrate user-provided birth data or retrieve untrusted remote content that influences later actions, increasing privacy and prompt-injection risk.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill explicitly requires collection of precise birth date, minute-level birth time, city of birth, and gender, then uses those inputs to generate intimate inferences about health, relationships, family, and children. Even if framed as astrology, this is sensitive personal data collection and profiling beyond a minimal transactional need, increasing privacy, misuse, and user-harm risk.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The retrospective validation section directs the agent to infer family structure, personality, and past major life events from the chart, which materially expands the activity into personal profiling and history reconstruction. That creates a stronger privacy invasion risk and may lead to manipulative or unfounded claims presented as validated personal facts.

Description-Behavior Mismatch

Low
Confidence
86% confidence
Finding
The skill instructs writing a named report file into an output directory, creating persistent storage behavior that is not clearly reflected in the high-level description. Because the report is tied to a person's name and contains highly sensitive personal analysis, this increases data retention and unauthorized access risk.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The framework’s knowledge-map explicitly includes highly personal topics such as relationship, family, spouse traits, and even '绿帽判断' that go beyond a minimal BaZi calculation or general horoscope-style analysis. This creates a structured pathway for the skill to infer or present intimate and potentially defamatory conclusions about users without clear necessity, consent, or safety boundaries.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill mandates generating and saving an analysis file that would include precise birth details and intimate life assessments, but provides no warning about local storage, persistence, or privacy implications. This is dangerous because users may unknowingly cause sensitive data to be written to disk where others or other tools can access it.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill requires binary gender classification as mandatory input and states the analysis cannot proceed otherwise, without offering user choice or accommodation for non-binary identities. This creates an exclusionary design and can pressure users into disclosing sensitive identity information in a false or unnecessary form.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
The output template hard-codes metadata to only 男/女, reinforcing binary-only handling and propagating sensitive identity data into saved artifacts. In context, this combines with persistent report writing to increase privacy and dignity risks for users whose identity does not fit the template.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill directs the agent to write a full birth-chart analysis to an output directory using a filename derived from the person's name, while the workflow also collects highly sensitive personal data such as birth date, birth time, birthplace, and gender. Storing this material without an explicit privacy notice, consent step, minimization rule, or retention guidance creates a clear privacy and data-handling risk, especially because output directories may be synced, logged, or exposed to other tools.

Natural-Language Policy Violations

High
Confidence
89% confidence
Finding
The skill requires analysis strictly on a male/female binary basis and states that interpretation must differ completely by those categories, with no user choice, accommodation, or justification beyond the domain's own assumptions. This creates a high risk of exclusion, misgendering, and harmful or inaccurate profiling, especially for users who are non-binary, transgender, intersex, or who do not want gender-based inference applied.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The skill codifies a gender-specific rule ('男财为妻,女官为夫') as a core principle without user choice, caveats, or acknowledgement of diverse identities and relationship models. In a system that generates personalized analysis from sensitive birth data, this can produce exclusionary or biased outputs, misgender users, and reinforce discriminatory assumptions as if they were authoritative guidance.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This template explicitly solicits a broad set of highly sensitive personal data, including full birth date/time, birthplace, and name, without any privacy notice, minimization guidance, or handling restrictions. In the context of an automated analysis skill, this creates avoidable privacy and profiling risk because the collected fields are sufficient for identification and sensitive inference.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The template hard-codes gender as '男 / 女', forcing a binary selection without explanation or accommodation for user choice. While not a code-execution issue, it can cause exclusion, inaccurate processing, and inappropriate handling of sensitive personal data in a skill that collects intimate profile information.

Natural-Language Policy Violations

High
Confidence
95% confidence
Finding
The framework hard-codes sex/gender-dependent interpretation rules as mandatory logic, causing the system to treat users differently based on gender without consent, validation, or accommodation for non-binary users. In a user-facing skill, this can produce discriminatory profiling and sensitive personal conclusions derived from a protected or sensitive attribute.

Natural-Language Policy Violations

High
Confidence
97% confidence
Finding
This section expands the gender-specific rules into multiple mandatory output behaviors, including different interpretations of marriage, children, and relationship dynamics for male and female users. Because these rules directly shape user-facing conclusions, they increase the risk of discriminatory treatment, stereotyping, and harmful personal assertions based solely on sex/gender classification.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The report template explicitly instructs the system to present gender-differentiated analysis to end users, operationalizing protected-attribute-based treatment in the final output. This makes the issue more dangerous because it is not just internal logic; it is a required presentation behavior that can directly expose users to biased or exclusionary content.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The text makes deterministic claims about marriage and family outcomes from a metaphysical framework without signaling that these are belief-based interpretations. In a skill that automates personalized analysis from birth data, such unqualified assertions can mislead users into treating speculative content as factual guidance about intimate relationships and life decisions.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
This passage makes categorical claims about health, inner stability, and personal capability as if they reliably follow from the described chart relation. Because the skill context is a comprehensive automated fortune-analysis system, users may over-trust these statements and make real personal or health-related judgments based on non-evidence-based content.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
The content assigns relationship roles such as '妻子(男命)' and '丈夫(女命)' as defaults without qualification, embedding heterosexual and gender-essential assumptions into what appears to be generalized guidance. In a user-facing interpretive system, this can alienate users, produce incorrect personalization, and reinforce biased outputs when the skill is applied broadly.

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
These sections repeatedly use fixed heterosexual and gendered relationship descriptions for spouse roles and traits without user opt-in, which can cause exclusionary or inaccurate outputs for users whose identities or relationships do not match those assumptions. Because the skill is designed to automate full-chart analysis, this bias is likely to propagate systematically across generated readings rather than remain isolated reference text.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The file presents astrology-based monthly predictions as deterministic guidance, using prescriptive phrasing such as favorable or unfavorable outcomes without caveats. In a skill positioned as a comprehensive decision framework, users may over-trust this content for real-life choices, which can lead to harmful or distorted decision-making.

Natural-Language Policy Violations

Medium
Confidence
98% confidence
Finding
The phrase '当天大凶,诸事不宜' is absolute, high-certainty advice that can discourage normal activities or influence important decisions without evidence. Because the skill markets itself as an expert system, this language increases the risk that users will treat superstition as authoritative operational guidance.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This section discusses highly sensitive topics including fertility difficulty, miscarriage, and child death risk in a deterministic divination context without any content warning or boundary-setting. In a consumer-facing skill, this can cause emotional distress and may encourage users to internalize speculative claims about reproductive outcomes as factual or medically meaningful.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This section predicts when a user is likely to conceive or have children, but provides no warning not to rely on it for health, fertility, or family-planning decisions. In the context of an astrology-style system marketed as a comprehensive analysis framework, users may give these predictions undue weight and delay medical care or make consequential reproductive choices based on non-evidence-based guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.