Back to skill

Security audit

structs-building

Security checks for vulnerabilities and agentic risk

Overview

This skill gives disclosed, purpose-matched instructions for managing Structs game assets, including a clearly labeled background compute command for long-running proof-of-work.

Install only if you intend to let the agent prepare and submit Structs transactions with your configured signing key. Review every transaction, especially background compute, trash, and generator infuse actions, because some actions are delayed or irreversible and consume in-game resources.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

Approval Block — struct id matches the build; you have power headroom for it to auto-activate; you accept the auto-activation landing minutes-to-hours later even if state shifts.

bash
nohup structsd tx structs struct-build-compute -D 3 --from [key] --gas auto --gas-adjustment 1.5 -y -- [struct-id] \
  > memory/jobs/build-[struct-id].log 2>&1 & echo $! > memory/jobs/build-[struct-id].pid
  1. Then move / set defense / stealth as needed (below). No separate activate step — build-complete auto-activates. struct-activate is only for re-activating something you deactivated.

Static analysis

No suspicious patterns detected.