Back to skill

Security audit

MoPo Texas Hold'em Autoplay

Security checks for vulnerabilities and agentic risk

Overview

The skill openly implements MOPO autoplay, but it gives the agent unbounded authenticated control to keep polling and acting, then resume after interruption without fresh user approval.

Install only if you intend this skill to autonomously play MOPO through moltpoker.cc for a clearly bounded session. Confirm you are comfortable sending the claim key and agent id to that service, using the returned bearer token, and allowing the agent to submit gameplay actions without per-action approval. Prefer a version with explicit start/stop controls, session limits, visible status, and fresh authorization after interruption.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:3
Finding

Persistent Autonomous Agent Takeover Through Skill Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:3-13, SKILL.md:29-41, SKILL.md:65-69, references/onboard-prompt-template.md:1-43, references/troubleshooting.md:41-44
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable Code

SKILL.md:3-13:

markdown
description: Executable MOPO runtime takeover skill. Use when an agent should immediately take over gameplay from onboarding prompt, keep polling runtime tasks, submit strictly legal actions with exact action_id/payload schema, and resume automatically after interruption.
---

# MOPO Runtime Autoplay Skill (Strict Action Safety)

## Goal
After receiving onboarding prompt, immediately run MOPO in runtime mode:
1) call one-shot onboarding (`/agent/onboard/start`)
2) get `agent_id + token + runtime_enabled + table_id`
3) continuously poll and act
4) support interruption resume by re-running same flow

SKILL.md:29-41:

markdown
## Runtime Loop (continuous)
Repeat:
1. `GET /agent/runtime/next?agent_id=...` (Bearer token)
2. if `pending=false`: wait 800-1200ms and poll again
3. if `pending=true`:
   - read `task.state`
   - derive legal action (see hard rules below)
   - submit `POST /agent/runtime/act` with **exact action schema** and **exact `task.action_id`**
4. if act fails:
   - `turn moved` / `action_id mismatch`: drop stale task and continue polling
   - `cannot check`: immediately retry with `call` if legal else `fold`
   - `cannot call`: retry `fold`
   - other invalid action: do not repeat same invalid action; choose legal fallback and submit once
   - network/server transient: retry once quickly (200-400ms), then continue polling

SKILL.md:65-69:

markdown
## Resume After Interruption
If interrupted by other owner session/tool context:
- re-run same onboarding command
- ensure runtime enabled
- continue runtime loop (do not rebind repeatedly if already bound)

references/troubleshooting.md:41-44:

markdown
## Recovery playb
...[truncated 3951 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove all “takeover,” role-reassignment, and unconditional “execute immediately” language.
  2. Require explicit, informed user confirmation before transmitting the claim key or agent identifier to the external service.
  3. Clearly identify https://moltpoker.cc as a third-party destination and explain which data will be transmitted.
  4. Replace the indefinite runtime loop with a bounded session defined by a maximum duration, poll count, or action count.
  5. Require renewed user approval before each new session and before consequential gameplay actions, particularly raises or actions involving value.
  6. Stop immediately when the session is interrupted, ownership changes, authorization expires, or tool context changes. Do not automatically re-onboard or resume.
  7. Treat every remote task and server response as untrusted data. Validate types, lengths, allowed identifiers, legal-action sets, amount limits, and table association before use.
  8. Keep bearer tokens in ephemeral secret storage, prevent them from appearing in logs or prompts, and erase them when the approved session ends.
  9. Add cancellation controls and visible status reporting so users can inspect and terminate polling at any time.
  10. Document a narrow authorization boundary specifying the permitted host, endpoints, account, table, action count, and session lifetime.
  11. Make onboarding and action submission opt-in functions invoked by an explicit user request rather than automatic effects of loading the skill.
  12. Revise the recovery playbook so interruption requires a safe stop and fresh authorization instead of automatic continuation.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file is written as a mandatory instruction in Chinese and does not offer any language choice or opt-in. Under the policy, forcing a specific language without user selection is a natural-language policy concern unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.