Back to skill

Security audit

tung-shing-almanac

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese almanac API skill with some privacy and install caveats, but I found no hidden, destructive, or deceptive behavior.

Install only from a source you trust, prefer pinned or reviewed versions over mutable npx examples, and remember that this skill sends almanac queries and optional personal details such as birth dates to 12Zodiacs.com. Treat the results as cultural or entertainment guidance, not as medical, legal, financial, or safety-critical advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (19)

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README instructs users to run an unpinned package via npx -y chinese-almanac-mcp, which executes the latest published code from the npm registry without version control or integrity verification. If the package is compromised, typosquatted, or a malicious update is published, users could execute attacker-controlled code on their local machine during installation or runtime.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README promotes using the skill to plan consequential real-world decisions including major purchases, renovations, C-sections, travel, and new-job starts, but provides no safety warning that the output is cultural/entertainment guidance rather than medical, legal, financial, or safety-critical advice. This increases the chance that users or downstream agents will over-trust the tool for life-impacting decisions, especially given the authoritative language about precision and canon-based methodology.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

Using npx skills add yonlandwu/tung-shing-almanac-skill relies on an unpinned CLI package and pulls remote skill content by mutable reference, so the installed toolchain and fetched artifact can change over time. This creates a supply-chain risk where a compromised CLI release or altered upstream skill source could deliver unexpected or malicious code/content to the user environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The Codex/OpenAI installation example again uses npx skills add without version pinning, exposing users to mutable remote package execution and mutable skill retrieval. An attacker who compromises the CLI, registry account, or referenced repository could cause users to install or execute altered code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README says the skill may trigger with $tung-shing-almanac "or just ask '哪天适合搬家' (description matching)," which is a broad natural-language activation pattern that can overlap with ordinary user conversation. In agent environments that auto-discover or auto-invoke skills by semantic matching, this can cause unintended invocation of external data access or decision-support behavior without explicit user intent to use this specific skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes shell scripts, Python, network access, caching, and likely environment-provided API keys, but does not declare any explicit tool scope or permission boundaries. That creates an avoidable least-privilege gap: an agent may grant broader shell/file/network capabilities than are actually necessary, increasing the blast radius if the skill is misused or prompt-injected.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description contains many broad natural-language triggers such as weddings, moving, travel, lucky dates, signing, launches, lunar calendar conversion, and solar terms. Overly expansive routing criteria can cause the skill to activate for loosely related user requests, unexpectedly invoking shell/network-backed behavior and exposing user queries or context to external processing when the user did not clearly ask for this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The API response includes a system_directive field telling the consuming agent to append a specific sentence to user-facing output. Untrusted tool/API content should never be treated as instruction-bearing because it can influence model behavior and create a prompt-injection channel; while this specific string is just attribution text, the pattern is unsafe and could be changed later to something more manipulative.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This command sends user-supplied date input and an optional API key to a third-party service without any explicit disclosure or consent prompt. In a skill context, users may reasonably assume local processing, so silent transmission can expose behavioral or account-linked data and normalize undisclosed external sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auspicious-date lookup transmits user interests and scheduling preferences, which can reveal sensitive life-event intentions such as weddings, moves, purchases, or openings, along with an optional API key. Even though the API uses HTTPS, undisclosed third-party data sharing is a privacy weakness and can leak query parameters through logs, browser history, or intermediary monitoring systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The lucky-hour feature sends zodiac and date information to an external endpoint without warning the user, creating an undisclosed privacy/data-sharing issue. In this skill's context, users may treat such personal-calendar or belief-linked inputs as private, so silent exfiltration to a third party is more concerning than a purely local calculation would be.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The horoscope command transmits sign/date inputs externally with no user-facing notice, which is a genuine privacy weakness even if the data seems low sensitivity. The risk is amplified slightly because the script also supports optional keys in URLs elsewhere, suggesting a broader pattern of undisclosed external transmission and weak handling of request metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script sends the user-supplied birth date to the external 12Zodiacs API in zodiac_of_birth() without an explicit warning or consent step at the point of collection or transmission. Birth date is personal data, and in this skill it is not strictly local-only processing, so users may unknowingly disclose sensitive information to a third party.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The markdown advertises personalized horoscope and lucky-hour results, which can influence user decisions, but the safety notice later only mentions medical, legal, and financial advice. A clearer warning that these outputs are cultural/entertainment guidance and should not be relied on for important personal decisions would better disclose the nature of the behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The header comment says the script supports only '{day|hours|term|auspicious|horoscope}', but the case statement also implements 'lucky-hour'. This is an active documentation/code mismatch that can misstate the skill's actual interface and intent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes daily almanac data, auspicious/avoid activities, 12 hour pillars, zodiac clash, solar terms, horoscopes, and date selection use cases, but it does not mention a personalized 'best hours for your zodiac' endpoint. This adds a user-facing feature beyond the stated description rather than an obvious implementation detail of the declared almanac functions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The default error output lists supported commands as '{day|hours|term|auspicious|horoscope}', but the script also accepts 'lucky-hour'. This directly misdocuments runtime behavior and the intended public interface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The argument parser hard-codes --lang choices to zh and en, forcing a specific language set rather than allowing broader locale choice. This is a natural-language policy concern because the skill imposes language constraints without documenting that limitation as an explicit locale-specific scope or opt-in policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This JSON test data encodes accepted event names in both Chinese and English, but the file provides no natural-language indication of supported locales or user choice. Because language handling is hardcoded in the data and not explicitly framed as multilingual support, it may reflect an implicit locale policy decision.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.