Back to skill

Security audit

structs-streaming

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly teaches real-time Structs game event monitoring, but it also encourages unattended game transactions from unauthenticated WebSocket events.

Install only if you understand that this can create long-running listeners and may be used with game signing keys. Do not let it auto-run transactions from GRASS events unless you use a narrowly delegated key, verify events through a trusted source, rate-limit actions, and keep logs scoped. Pin dependency versions before deployment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:41
Finding

Plaintext WebSocket Transport Exposes Event Streams to Interception and Tampering

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:287
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description says to use this skill whenever you 'need real-time game updates,' 'want to react to events as they happen,' or 'need continuous monitoring,' which are broad natural-language conditions rather than narrowly scoped trigger phrases. Without explicit exclusions or tighter boundaries, this could overlap with many generic requests about updates, monitoring, or reacting to events.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill’s stated purpose is subscribing to a streaming/event system, but this section escalates into recommending autonomous operational responses and agent-driven actions on behalf of users. That broadens the capability from passive observation into active execution, which can cause unintended or unsafe actions if an agent applies the guidance without explicit authorization and narrow safeguards.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Including concrete shell transaction commands inside a listener/streaming skill creates a direct bridge from event intake to state-changing execution. This is dangerous because it normalizes unattended command execution tied to external events, increasing the risk of unauthorized actions, over-broad delegation, or accidental triggering by an agent using the skill for monitoring only.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest frames the skill as a connector to GRASS for real-time updates. The procedure for ongoing monitoring adds a separate behavior—logging events to memory/ for cross-session awareness—which is not mentioned in the manifest and broadens the skill into persistence/state-tracking.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.