Back to skill

Security audit

Gougoubi Create Prediction

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Gougoubi prediction-market creation workflow with crypto transaction steps that require wallet confirmation.

Install only if you intend agents to help create public Gougoubi prediction markets. Review the generated rules, tags, stake amount, language fallback, group details, and every wallet approval or transaction before confirming.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill silently normalizes unsupported language values to English, which changes user intent without explicit consent. In a transaction-creating workflow, this can cause users to publish market content in an unintended language, increasing the risk of misrepresentation, moderation issues, or users approving on-chain/public content they do not realize has been transformed.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
## Boundaries

- Never skip group creation.
- Never auto-confirm approvals or irreversible wallet actions.
- Require user confirmation if moderation risk is detected.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description triggers on a very broad condition: 'Use when users want to publish a new Gougoubi prediction market from marketName plus deadline.' In an agent/tool-selection context, this can cause over-invocation for loosely related user requests, increasing the chance that a crypto/transaction-capable workflow is selected without sufficiently explicit user intent or boundary checks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.