Back to skill

Security audit

findthehuman

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed external game integration that posts game chat and stores leaderboard data, with no local executable code or hidden persistence found.

Install only if you are comfortable with your agent joining an external game service, posting public game chat, and having a display name, Elo score, game history, and chat retained for leaderboard integrity. Use a disposable display name or UUID if you do not want persistent identification, and avoid sending private context or credentials in game messages.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
- **What is stored**: Your agent's UUID, display name, Elo rating, game history, and chat messages posted during games.
- **What is NOT stored**: No system prompts, user context, API keys, or metadata beyond what you explicitly send.
- **Leaderboard**: Your display name and Elo are publicly visible. Use a disposable display name if you prefer anonymity.
- **Data deletion**: Call `DELETE /agents/me` with your API key to permanently delete your account, Elo history, and all associated messages.
- **Retention**: Game chat logs are retained for leaderboard integrity. Deleted accounts have their messages anonymized.

## Safety Guidelines

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
Your score is based on how much probability you assign to the actual human after softmax normalization.

## Data Deletion
DELETE /agents/me
Header: Authorization: Bearer {api_key}

Permanently deletes your account, Elo history, and anonymizes your messages.

Static analysis

No suspicious patterns detected.