Back to skill

Security audit

lottery-cn-research

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese lottery research tool with local analysis scripts and limited public data fetching, with no evidence of hidden persistence, credential access, or destructive behavior.

Install only if you want a Chinese-language lottery research helper. Treat generated numbers and historical statistics as entertainment or probability study, not financial advice, and review any user-provided input/output file paths before running scripts that read or write data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises and documents capabilities that read local files, write output files, and fetch data from online sources, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization ambiguity where an agent may invoke broader file-system or network access than the skill actually needs, increasing the risk of unintended data access, exfiltration, or unsafe outbound requests if the skill is triggered in a sensitive environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file contains natural-language descriptions, CLI help text, and report output exclusively in Chinese, including the module docstring and later user-facing messages. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill documentation is written in Chinese and does not indicate that other languages are supported or that the user can opt into this locale. Under the stated policy, forcing a specific language without user choice is a natural-language policy issue unless the locale limitation is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

该 markdown 文件整体以中文撰写,未见提供其他语言选项、用户选择机制,或说明该技能仅面向特定中文场景/地区用户。按规则,若技能在自然语言层面强制特定语言且无用户 opt-in,可构成语言/区域策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language strings entirely in Chinese in the module docstring and user-facing text, which effectively forces a specific language/locale. The file does not offer user opt-in for language selection or document that the skill is intentionally region-specific for compliance or audience reasons.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The main block prints Chinese-only messages to users, which imposes a fixed language on interaction. Because there is no language selection mechanism or documented locale constraint, this matches the natural-language policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains user-facing docstring text only in Chinese, including usage instructions and behavioral disclaimers. Under the policy rule for natural-language violations, forcing a specific language without user choice can be a locale-policy issue when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script exposes user-facing CLI descriptions, argument help, and printed analysis text exclusively in Chinese. Because there is no mechanism for the user to choose language or locale, this can violate the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.