Back to skill

Security audit

Game Account Price Trends

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for generating marketplace reports, but it embeds a reusable API signing value and directly renders untrusted marketplace text into Markdown.

Review before installing. The market-reporting behavior is understandable, but the publisher should remove or replace the embedded signing value and escape externally sourced marketplace text before returning Markdown reports. Users should treat listing text and links in reports as untrusted marketplace data, not as agent instructions or verified recommendations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_mall_trade_data.py:16
Finding

Hardcoded API Signing Secret Enables Application Impersonation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_market_overview.py:39
Finding

Untrusted Marketplace Content Is Rendered as Unsanitized Markdown

Content
View full analysis
Remediation
View remediation
` in all remote text. - Do not permit raw HTML from API responses to enter generated reports. 3. **Validate link identifiers** - Convert `goodsId` to a string and require it to match the documented identifier format, such as a strict numeric or UUID pattern. - Omit the detail link when validation fails. - URL-encode validated path and query components where appropriate. 4. **Separate data from instructions** - Clearly label listing text as externally sourced data. - Ensure Agent instructions explicitly state that remote listing content must never be followed as instructions. - Consider rendering remote text in escaped code spans or another inert representation. 5. **Add security tests** - Test payloads containing Markdown links, image syntax, HTML, table pipes, nested brackets, parentheses, backticks, and instruction-like text. - Verify output in every supported Markdown client to ensure remote content cannot create active links or external resource loads except for intentionally generated, validated detail links. ]]>
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

python3 scripts/generate_market_overview.py /tmp/mall-market-overview.json

text

## Output rules

- Return the generated Markdown report directly.
- Do not paste raw JSON unless the user explicitly asks.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to run local scripts that read files and perform network access, but it does not declare any explicit tool scope or permission boundary. That creates an authorization gap where the agent may invoke broader capabilities than the skill metadata makes visible, increasing the chance of unintended data access or outbound requests if the skill or its bundled code changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.