Back to skill

Security audit

lol-analyst

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it stores a Riot API key in a local plaintext config file without clear permission protections or adequate warning.

Review this skill before installing if you are not comfortable storing a Riot API key in plaintext under your home directory. Prefer using the RIOT_API_KEY environment variable, avoid passing keys directly in shell commands where history or logs may capture them, and install dependencies in an isolated virtual environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/config_manager.py:76
Finding

Riot API Key Stored in Plaintext Without Enforced Access Restrictions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unbounded Third-Party Dependency Resolution

Content
View full analysis
=3.2.0 ``` The documentation also recommends an unconstrained installation: ```bash pip install riotwatcher ``` ### Technical Analysis The requirement permits any current or future `riotwatcher` release at or above version 3.2.0. No exact version, upper bound, lock file, package hash, or trusted package-index restriction is provided. As a result, installation is not reproducible and may retrieve code that was not part of the reviewed project state. Risk arises if a future package release or a configured package index is compromised, if a malicious mirror is used, or if a future release introduces incompatible or vulnerable behavior. Python packages can execute code during installation and subsequently run with the privileges of the Python process when imported. The project imports `riotwatcher` directly in `scripts/riot_client.py`, so a malicious resolved package would be loaded during normal execution. ### Attack Path 1. A user follows the project instructions and runs `pip install riotwatcher` or installs from `requirements.txt`. 2. Pip consults the environment's configured package index and resolves the newest version satisfying `>=3.2.0`. 3. A compromised future release, malicious mirror, or attacker-controlled configured index supplies an unsafe package. 4. Package code executes during installation or when `riotwatcher` is imported. 5. The malicious dependency operates with the privileges and data access of the user running pip or the Skill. This attack path requires compromise or manipulation of the dependency distribution channel; the audited source does not itself retrieve or execute an independent remote payload. ### Impact Assessment A malicious dependenc ...[truncated 412 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description says the skill '支持中文自然语言查询', which presents a language constraint in the skill’s natural-language behavior. Under the policy, forcing or implying a fixed language without offering a choice or documenting opt-in can be a locale/language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares environment-variable use and describes reading/writing local HTML output files, but it does not define any explicit tool scope such as allowed tools or permissions. That omission weakens least-privilege controls and can let the host agent invoke file and environment capabilities more broadly than users would expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest includes broad trigger phrases like '英雄联盟', 'LOL数据', and '排位分析', which may match ordinary conversation and cause the skill to activate unexpectedly. Over-broad activation can expose user data to the skill, prompt unwanted API usage, or cause the agent to follow this skill when the user did not intend it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file states the skill supports Chinese natural-language queries, and later operational guidance instructs WorkBuddy to interpret results for the user in Chinese. This imposes a specific language behavior without indicating user opt-in or offering an alternative locale choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction “用中文给用户解读关键数据” mandates a specific output language in the integration flow. Because no opt-in or locale selection mechanism is provided, this is a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The default configuration hard-codes default_language to zh_CN, and the file’s strings and labels are Chinese-only. This imposes a specific language/locale by default without offering user choice or documenting that the tool is intentionally region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code persists the Riot API key in plaintext JSON under the user's home directory, which can expose the credential to other local users, backups, sync services, or malware if file permissions are weak. In this skill's context, the secret is an external API credential rather than a harmless preference, so silent local storage increases the chance of unintended disclosure and API abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring, CLI description, help text, and user-facing messages are all written exclusively in Chinese, which imposes a specific language experience on users. There is no indication that the skill offers language selection, opt-in, or that the locale restriction is required for a region-specific compliance reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The generated HTML explicitly sets lang="zh-CN", and the surrounding titles, labels, and content are all hard-coded in Chinese. This enforces a specific language/locale choice in user-facing output without offering a language selection or documenting that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This HTML template also hard-codes lang="zh-CN" and presents all visible report text in Chinese. That creates a language/locale policy issue unless the user has chosen Chinese or the tool is clearly documented as China-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The analysis report declares lang="zh-CN" and uses Chinese-only UI strings throughout the generated page. This is a user-facing locale restriction that lacks any visible opt-in or clear justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module description and surrounding natural-language text are entirely in Chinese, including the stated purpose of returning Chinese champion names, with no indication that language is configurable or chosen by the user. This can violate language/locale policy when a skill implicitly forces a specific language without offering opt-in or alternatives.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency is specified with a lower bound only (riotwatcher>=3.2.0), allowing future unreviewed versions to be installed. This can introduce supply-chain risk through breaking changes or a newly vulnerable or compromised upstream release, especially because this skill relies on an external API client library.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
riotwatcher>=3.2.0

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code makes multiple Riot API requests for summoner, account, match history, match detail, ranked, and mastery data, which transmit user-supplied identifiers and retrieve player data. In this file there is no confirmation prompt, logging/print statement, or comment/docstring warning users that these lookups contact an external service and process player identifiers.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:38