Back to skill

Security audit

Football Data Hub

Security checks for vulnerabilities and agentic risk

Overview

This football data skill is mostly purpose-aligned, but it requests broad file-editing and shell authority that is not needed for a read-only sports lookup tool.

Review before installing. The football data behavior itself is not deceptive, but the skill should ideally remove Write/Edit/Grep/WebSearch, constrain Bash to the bundled scripts, restrict network use to documented football APIs, and pin dependencies. Expect the zero-config OpenLigaDB features to work better than the advertised API-key player/H2H features.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:5
Finding

Skill Grants Tools Beyond Its Read-Only Football Data Function

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unbounded Third-Party Dependency Versions Create Supply-Chain Exposure

Content
View full analysis
=2.28.0 pyyaml>=6.0 ``` Related installation guidance: ```bash pip install requests pyyaml ``` ### Technical Analysis The project specifies only minimum dependency versions and provides no upper bounds, exact lock file, or package hashes. Consequently, each installation can resolve to a different and potentially unreviewed future release. The named packages are established packages from the normal Python ecosystem, and the project does not configure an unknown package index or use suspicious package names. There is therefore no evidence that a malicious dependency is intentionally included. The issue is that dependency authenticity and reproducibility are not enforced after package resolution. If a permitted package version, transitive dependency, package-index account, or configured installation source is compromised, installation can execute package build or installation logic with the privileges of the user running `pip`. A future incompatible release could also alter runtime security behavior. ### Attack Path 1. A user follows the documented installation command or installs from `requirements.txt`. 2. `pip` resolves the newest available versions satisfying `requests>=2.28.0` and `pyyaml>=6.0`. 3. A compromised or otherwise unsafe future release is selected from the configured package index. 4. Package installation or subsequent import executes the compromised dependency code. 5. That code runs with the permissions of the installation or Skill runtime account. This exploitation path requires compromise of a dependency, its distribution channel, or the user's configured package source; no such compromise was identified in the audited repository. ### Impact Assess ...[truncated 414 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description generally matches the domain and broad intent: this is indeed a football information query tool, and there is no evidence of betting, exfiltration, or unrelated malicious behavior. However, there is a material description-to-behavior mismatch because key advertised capabilities are not actually implemented in the code path that runs. The main function only provides real functionality for standings, fixtures, leagues, and limited team lookup through OpenLigaDB. For players and h2h, the script explicitly prints that OpenLigaDB does not support them and suggests configuring API-Football, but the API-Football and football-data.org modes are themselves marked '待实现' and do not execute those features. So the declared description overstates current functionality, especially around player data and H2H/pre-match preview. This is a meaningful mismatch in capabilities, though not a safety issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The primary skill description is written in Chinese with no indication that other languages are supported or that the user can opt into a preferred language/locale. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 7)May include surrounding context.

🚀 零配置,立即可用

无需注册、无需 API Key。基于 OpenLigaDB 免费公开数据。

bash
# 德甲积分榜

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description lists generic triggers such as “查赛程”, “球队信息”, “球员数据”, and “查排名”, which are common football-related requests rather than narrowly scoped activation phrases. There are no exclusion conditions or context limits, so the skill could be invoked unintentionally during ordinary conversation about football.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The dedicated trigger section provides a list of example phrases, but it does not explain when the skill should not activate or how these triggers differ from general sports discussion. This lack of specificity makes the invocation boundary unclear and increases the chance of accidental activation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file presents all user-facing guidance in Chinese and sets a default timezone of Asia/Shanghai, which imposes a specific language/locale context without offering alternatives or documenting that the skill is region-specific. This matches the policy category for language or locale constraints lacking user choice or clear justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and usage examples present this as a three-tier football data hub capable of standings, fixtures, teams, players, H2H, and multiple providers. In practice, the main execution path only implements OpenLigaDB queries, while API-Football and football-data.org branches merely print '待实现', and OpenLigaDB explicitly does not support players or H2H.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This is a natural-language policy issue because the file forces a specific language for usage examples and CLI guidance. The policy says to flag language or locale constraints unless the skill offers user opt-in or clearly documents a justified regional scope, which is not present here.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · config.example.yaml (reported line 16)May include surrounding context.

yaml
# ──────────────────────────────────────────────────────────────────────────

class FootballDataClient:
    BASE_URL = "https://api.football-data.org/v4"

    def __init__(self, api_key: str):
        self.session = requests.Session()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch_football_data.py (reported line 280)May include surrounding context.

python
# ──────────────────────────────────────────────────────────────────────────

class FootballDataClient:
    BASE_URL = "https://api.football-data.org/v4"

    def __init__(self, api_key: str):
        self.session = requests.Session()

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains natural-language instructions and output strings only in Chinese, starting with the module docstring and continuing throughout the CLI interface. Under the policy, forcing a specific language without offering user choice or documenting a justified locale restriction is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The H2H summary counts every historical home win as a win for team1 and every away win as a win for team2, instead of checking whether team1 or team2 was actually the home side in each prior match. This produces objectively incorrect comparative stats in a script presented as a factual pre-match analysis, which can mislead users and downstream agents relying on the report.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file uses Chinese headings and labels throughout, which can amount to a language-policy concern when a skill or reference forces a specific language without user opt-in. There is no indication that the content is intentionally region-specific or that alternative language support is offered.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency specifier requests>=2.28.0 is unpinned, so builds may resolve to different versions over time and can inadvertently pull in a vulnerable or incompatible release. This weakens supply-chain reproducibility and makes it hard to verify whether deployed environments are protected from known advisories affecting Requests.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.28.0
pyyaml>=6.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
87% confidence
Finding

Requests has multiple historical advisories, and because the manifest does not pin an exact version, it is not possible to verify from this file whether the installed package is affected. While this file alone does not prove exploitation, the lack of version pinning creates supply-chain uncertainty and may expose the skill to known flaws depending on resolution time.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency specifier pyyaml>=6.0 is unpinned, which allows non-deterministic installs and makes it uncertain which exact release will be used. Given PyYAML's history of deserialization-related issues, leaving the version open increases the chance of introducing a vulnerable release into the environment.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.28.0
pyyaml>=6.0

Unverifiable Dependency: pyyaml has 8 known advisory(ies) (CVE-2019-20477 (Deserialization of Untrusted Data in PyYAML); CVE-2020-1747 (Improper Input Validation in PyYAML); CVE-2020-14343 (Improper Input Validation in PyYAML) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

PyYAML has several known advisories, including unsafe deserialization risks, and the unpinned requirement prevents determining whether a safe release will be installed. In a data-query skill that may parse external data or configuration, this uncertainty is a real though low-severity supply-chain concern from the manifest alone.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The docstring for get_client describes returning a client by priority, implying those returned clients will support the advertised behavior. However, when source is 'api-football' or 'football-data', main only prints that those modes are not implemented, so the documented intent of operational provider selection contradicts actual behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.