Back to skill

Security audit

Football Data

Security checks for vulnerabilities and agentic risk

Overview

This football data skill is mostly purpose-aligned, but its setup asks users or agents to install unpinned code, including from a mutable GitHub repository.

Review before installing. Use an isolated virtual environment, prefer a pinned reviewed PyPI release, avoid the GitHub fallback unless pinned to a specific commit you trust, and do not expose unnecessary credentials or sensitive files to the environment running the installed CLI.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Third-Party Package Installation from Mutable Sources

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20–24
Vulnerability Type: Supply-chain risk caused by unpinned dependency installation
Risk Level: Medium

Vulnerable Code

bash
which sports-skills || pip install sports-skills
bash
pip install git+https://github.com/machina-sports/sports-skills.git

Technical Analysis

The Skill instructs the Agent to install sports-skills without pinning an exact package version or validating package hashes. If installation from the package index fails, it directs the Agent to install code from the GitHub repository's mutable default branch rather than from a reviewed commit.

Python package installation can execute package-controlled build or installation logic. Furthermore, the installed CLI will execute upstream code when subsequently invoked. The effective code therefore may differ from what existed when this Skill was audited.

The which sports-skills || pip install sports-skills construction also makes installation the immediate fallback whenever the executable is absent, increasing the likelihood that unreviewed remote code will be fetched and run.

No evidence indicates that the current upstream package is malicious. The vulnerability is the absence of version pinning, integrity verification, and provenance controls.

Attack Path

  1. An attacker compromises the package-index release, an upstream maintainer account, or the GitHub repository.
  2. The attacker publishes malicious package content or changes the repository's default branch.
  3. The Agent loads this Skill on a system where sports-skills is not installed, or package-index installation fails.
  4. The Agent follows the setup instructions and downloads the attacker-controlled package or repository state.
  5. Package build or installation logic executes, or the malicious code executes when the installed CLI is invoked.
  6. The payload runs with the privileges and environmental access of the user operating the Agent ...[truncated 634 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin sports-skills to an exact, reviewed release rather than installing the latest available version.

  2. Maintain a locked requirements file containing cryptographic hashes and install it with hash enforcement, for example:

    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  3. If Git installation is unavoidable, pin a full reviewed commit SHA rather than a branch or tag:

    bash
    python3 -m pip install \
      git+https://github.com/machina-sports/sports-skills.git@FULL_REVIEWED_COMMIT_SHA
    
  4. Verify release provenance, signatures, or attestations where the upstream distribution mechanism supports them.

  5. Replace automatic fallback installation with an explicit confirmation step that displays the source, exact version or commit, and expected integrity value.

  6. Install the dependency in an isolated virtual environment with minimum filesystem and credential access.

  7. Review dependency updates before changing the pinned version or commit, and update integrity hashes only after approval.

Vulnerability Patterns
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
94% confidence
Finding

The skill instructs the agent/operator to install executable code directly from a GitHub repository via pip install git+https://..., which bypasses pinned, audited package distribution and executes arbitrary package build/install logic from a moving remote source. In an agent skill context, bootstrap instructions that fetch and run remote code materially increase supply-chain risk, especially if the repository, dependency chain, or referenced branch is compromised.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

use get_event_xg for leagues outside the top 5 (EPL, La Liga, Bundesliga, Serie A, Ligue 1). license: MIT metadata: author: machina-sports version: "0.1.0"

Football Data

Setup

Before first use, check if the CLI is available:

bash
which sports-skills || pip install sports-skills

If pip install fails (package not found or Python version error), install from GitHub:

bash
pip install git+https://github.com/machina-sports/sports-skills.git

The package requires Python 3.10+. If your default Python is older, use a specific version:

bash
python3 --version  # check version
# If < 3.10, try: python3.12 -m pip install sports-skills
# On macOS with Homebrew: /opt/homebrew/bin/python3.12 -m pip install sports-skills

No API keys required.

Quick Start

Prefer the CLI — it avoids Python import path issues:

bash
sports-skills football get_daily_schedule
sports-skills football get_season_standings --season_id=premier-league-2025

Python SDK (alternati

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation declares get_head_to_head in the 'ONLY valid commands' list, but later marks it as 'UNAVAILABLE — requires licensed data. Do not call this command.' This inconsistency can cause an agent to invoke a disabled or unauthorized tool path, leading to failed executions, policy bypass attempts, or unintended access to licensed functionality if backend enforcement is weak.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.