Back to skill

Security audit

Game Account Valuation

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent game-account valuation tool, but it asks users to use QR login and sends account-related data over an insecure HTTP service with limited privacy warning.

Review this carefully before installing. Only use it if you are comfortable sending game-account details and QR-login workflow data to the listed third-party valuation service, and avoid using it on untrusted networks unless the endpoint is changed to HTTPS and the QR handling is tightened.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/valuation.sh:165
Finding

Unconditional Commercial Content Injection into Valuation Reports

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/valuation.sh:4
Finding

Sensitive Authentication and Account Data Transmitted over Plaintext HTTP

Content
View full analysis
&2 echo "Error: 获取二维码失败" >&2 exit 1 fi opened=$(save_and_open_qrcode "$qrcode" "$login_uuid") echo "二维码已打开:${opened}" >&2 echo "请用手机扫码并确认登录,扫码成功后会自动查询估值。" >&2 wait_for_scan "$login_uuid" >/dev/null local final_body final_body=$(python3 -c 'import json,sys; d=json.loads(sys.argv[1]); d["login_uuid"]=sys.argv[2]; print(json.dumps(d, ensure_ascii=False))' "$body" "$login_uuid") cmd_query "$final_body" | python3 -c 'import json,sys; d=json.load(sys.stdin); d["game"]=sys.argv[1]; print(json.dumps(d, ensure_ascii=False))' "$game" | format_report } ``` ### Technical ...[truncated 2061 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/valuation.sh:35
Finding

Authentication QR Artifacts Stored in a Predictable Shared Temporary Directory

Content
View full analysis
"$image_path" 2>/dev/null; then open_target "$image_path" printf '%s\n' "$image_path" return fi local text_path="${QRCodeDir}/qrcode_${login_uuid}.txt" printf '%s\n' "$qrcode" > "$text_path" open_target "$text_path" printf '%s\n' "$text_path" } ``` ### Technical Analysis The script stores QR authentication material under the fixed path `/tmp/game-valuation-qrcode`. It does not set a restrictive `umask`, create a per-process private directory, use exclusive file creation, check for symbolic links, or remove artifacts when execution ends. The filenames incorporate a server-provided `login_uuid` without local validation. Although quoting prevents shell word splitting and command injection, it does not prevent path separators or traversal sequences from affecting the generated path if the remote service is malicious or its response is modified. Normal shell redirection follows symbolic links. On a multi-user system, another local user may pre-create predictable paths or monitor the shared directory. The exact consequences of overwriting a target file depend on the victim process's permissions. ...[truncated 1400 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:37
Finding

Unpinned Installation from Mutable Package and Repository Sources

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README states that account valuation requests are sent to an external http:// service without clearly warning users that account-related information will leave the local environment. Using plain HTTP also exposes those details to interception or tampering in transit, making the privacy and integrity risk materially worse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The QR-code login and polling flow accesses account-linked data through an external service, but the README provides no warning about the trust boundary, privacy implications, or phishing-like risks inherent in asking users to scan a login QR code. In this skill context, that omission is significant because users may treat the flow as first-party and expose account access or metadata to a remote operator.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README says the skill can be triggered by phrases like 「我的号值多少钱」 and similar examples, which are broad conversational phrases rather than narrowly scoped commands. It does not provide clear constraints or exclusion conditions, so the trigger could match ordinary chat and cause unintended invocation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes shell scripts and even includes an open command, but it declares no tool scope or permissions boundary. That means an agent may gain shell-capable behavior without explicit least-privilege controls, increasing the risk of unintended command execution, external network access, and unsafe side effects if the skill is triggered or modified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description and user-facing guidance do not clearly warn that some flows require QR-code login and send account-related data to external services. Users may be induced to authenticate or disclose game-account identifiers without informed consent, which raises privacy, account-security, and phishing-style trust risks, especially because the service uses a non-obvious external HTTP endpoint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The default BASE_URL uses plain HTTP, so account-related identifiers, login UUIDs, polling traffic, and valuation query data are transmitted without transport encryption or server authentication. A network attacker could intercept or modify requests and responses, potentially hijacking sessions, altering QR/login flow behavior, or harvesting sensitive account metadata.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script exposes helper commands for qrcode, poll, and especially a raw query path that bypass the higher-level workflow described by the skill metadata. In an agent setting, these low-level primitives expand the skill’s effective capability surface and can be abused to send arbitrary request bodies to the backend or automate login-state polling outside the intended single-account valuation flow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script stores QR code data and fallback text files in /tmp and opens them automatically, which can expose sensitive login artifacts to other local users or processes on shared systems. Because /tmp is a shared location and the files are named predictably from login_uuid, local disclosure or tampering risk is increased, especially in multi-user or less trusted environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.