Back to skill

Security audit

HerGünMaç - Football Prediction Engine

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its football-analysis purpose, but it tells the agent to fetch and use a live remote instruction file that can change after review.

Review this skill before installing because its live llm.txt navigation file can change outside the reviewed package. Use it for hergunmac.com football prediction lookups, keep betting outputs informational, and do not follow remote instructions that ask for credentials, payment actions, local files, unrelated domains, or changes to agent behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:27
Finding

Mutable Remote Instructions Can Influence Agent Behavior

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 27-31
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: Medium

Complete Code Snippet:

markdown
## Navigation Reference

**Live context file:** https://www.hergunmac.com/llm.txt

Fetch the latest navigation guide directly from the site for up-to-date URL patterns, UI elements, and browser automation notes.

Technical Analysis

The skill explicitly instructs the agent to retrieve a remotely hosted text file and use it as a navigation and browser-automation guide. Unlike the bundled reference, the remote file is not immutable, version-pinned, integrity-checked, or included in the audited package.

Because this resource is intended for consumption by an LLM, instructions introduced into it could be interpreted as trusted operational directives rather than untrusted website content. A party controlling the domain, web server, deployment pipeline, or /llm.txt resource could modify the agent's browser behavior after the skill has been reviewed. This creates a prompt-injection and instruction-hijacking boundary.

The audited package does not contain an executable remote payload, credential-stealing logic, persistence mechanism, or direct data-exfiltration implementation. Therefore, this is classified as instruction hijacking rather than remote code execution.

Attack Path

  1. A user activates the skill with a football prediction or match-analysis request.
  2. The agent follows the instruction in SKILL.md and fetches https://www.hergunmac.com/llm.txt.
  3. An attacker who has compromised or legitimately controls the remote resource changes it to include malicious LLM instructions.
  4. The remote instructions direct the agent toward attacker-selected pages or actions, potentially requesting sensitive information or attempting to override the original task and safety constraints.
  5. If the agent treats the remote guide as authori ...[truncated 805 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction to fetch and follow the live LLM context file automatically.
  2. Prefer the bundled, reviewed references/llm-context.md file as the authoritative navigation guide.
  3. If remote updates are required, pin the resource to a reviewed version and verify it using a trusted cryptographic digest or signature.
  4. Treat all remotely fetched content as untrusted data, never as higher-priority agent instructions.
  5. Parse remote navigation data through a strict schema that accepts only necessary fields, such as allowlisted routes and UI labels, while rejecting free-form instructions.
  6. Restrict browser navigation to the expected HTTPS origin and an explicit allowlist of routes.
  7. Prevent remote content from requesting credentials, changing safety constraints, invoking unrelated tools, accessing local files, or initiating transactions.
  8. Require explicit user confirmation before performing sensitive browser actions or leaving the allowlisted domain.
  9. Maintain a reviewed local fallback and fail closed when integrity or validation checks do not pass.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation description is broad enough to trigger on many ordinary sports or betting-related queries, which can cause the agent to invoke this external-site skill more often than necessary. That increases the chance of unintended browsing, over-collection of third-party content, and responses being shaped by an untrusted source when a general knowledge answer would have sufficed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document states 'Primary Language: Turkish (tr-TR)' as a fixed language constraint. Under the policy, forcing a specific language without user opt-in or an explicitly justified locale restriction is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The navigation instructions require use of Turkish UI labels like 'Yaklaşan', 'Canlı', 'Bitti', and tab names in Turkish, but the document does not explicitly offer an alternative language or opt-in for locale-specific behavior. This can conflict with a language/locale policy if users are expected to operate in another language context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.