Back to skill

Security audit

紫微识人管人报告生成

Security checks for vulnerabilities and agentic risk

Overview

This skill is not malware, but it creates and stores sensitive employee profiles from birth data and workplace context without clear consent, retention limits, or sharing controls.

Install only if you are comfortable with a skill that can collect birth details, gender, workplace role, reporting relationships, and incident history to create employee management profiles. Before use, require explicit consent from the subject, avoid entering data into third-party charting sites unless approved, disable default MEMORY.md updates and forwarding, and define who can read the saved reports and when they must be deleted.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill's stated purpose is report generation, but it additionally instructs the agent to persist reports, update a memory file, and share output for review. This expands the data lifecycle from transient analysis to durable profiling without clear necessity, consent, retention limits, or access controls, creating unnecessary privacy and insider-exposure risk.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
Updating `MEMORY.md` creates a long-lived personnel dossier that is broader than what is needed to answer a single report request. Because the skill processes birth data, gender, job context, and inferred behavioral weaknesses, this instruction turns a one-off analysis into ongoing sensitive profiling with elevated privacy and misuse risk.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill asks for highly sensitive personal data, including full birth date/time, gender, employment context, and recent incidents, then later directs writing reports to files, but gives no privacy notice or storage warning. In this context, the data is sufficient to create identifiable, sensitive employee profiles and behavioral inferences, so silent collection and persistence materially increases privacy, compliance, and trust risks.

Missing User Warnings

Medium
Confidence
99% confidence
Finding
The skill instructs use of an external online charting site for natal-chart generation without warning that the subject's birth data and gender will be transmitted to a third party. Because these are highly sensitive identifiers and the analysis is for employee-management profiling, undisclosed off-platform transfer meaningfully raises confidentiality, compliance, and third-party handling risks.

Ssd 3

High
Confidence
99% confidence
Finding
The skill is designed to collect and analyze sensitive personal information to infer personality, weaknesses, and management tactics, then preserve the resulting dossier. In the context of employee evaluation, persistent storage of such raw inputs and derived inferences can enable discriminatory profiling, unauthorized access, and long-term misuse well beyond the immediate task.

Ssd 3

High
Confidence
98% confidence
Finding
The archiving and propagation instructions explicitly tell the agent to save personal dossiers across files and potentially send them onward for review. This creates multiple copies of sensitive employee assessments, expanding the attack surface and making unauthorized disclosure, internal misuse, and data sprawl substantially more likely.

Static analysis

No suspicious patterns detected.