Back to skill

Security audit

rhythm-master

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent rhythm game skill, but its optional online leaderboard includes unsafe Firebase guidance and remote leaderboard rendering issues that need review before public use.

Use the local HTML game with awareness that player names and scores are saved in the browser. Do not deploy the online leaderboard as written: require authenticated or server-mediated score submission, deny public database writes by default, validate all fields, render leaderboard values as text rather than HTML, and add a clear privacy notice before collecting or publishing player data.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
assets/rhythm-game.html:952
Finding

Stored DOM-Based Cross-Site Scripting in the Local Leaderboard

Content
View full analysis
{ const row = document.createElement('tr'); const rankClass = index < 3 ? `rank-${index + 1}` : ''; row.innerHTML = ` ${index + 1} ${entry.playerName} ${entry.score.toLocaleString()} ${entry.maxCombo} ${entry.difficulty.toUpperCase()} ${entry.date} `; tbody.appendChild(row); }); ``` ### Technical Analysis The leaderboard reads JSON records from `localStorage` and interpolates their properties directly into an HTML template assigned to `row.innerHTML`. No output encoding, schema validation, or type validation is applied to `playerName`, `score`, `maxCombo`, `difficulty`, or `date`. Although the visible player-name input has a `maxlength` attribute, this is only a user-interface restriction. Browser storage is mutable and is not a trusted security boundary. A malicious or corrupted leaderboard record can therefore contain HTML elements with executable event handlers. When `showLeaderboard()` renders such a record, the browser parses the attacker-controlled value as markup rather than displaying it as plain text. ### Attack Path 1. An attacker or another same-origin script places a crafted JSON record in the `rhythmLeaderboard` local-storage key. 2. The victim opens the local leaderboard. 3. `showLeaderboard()` parses the stored record. 4. Attacker-controlled record properties are inserted into `row.innerHTML`. 5. The browser parses the injected ...[truncated 839 chars]
Remediation
View remediation
{ const row = document.createElement('tr'); const rankClass = index < 3 ? `rank-${index + 1}` : ''; appendTextCell(row, index + 1, rankClass); appendTextCell(row, entry.playerName); appendTextCell(row, entry.score.toLocaleString()); appendTextCell(row, entry.maxCombo); appendTextCell(row, entry.difficulty.toUpperCase()); appendTextCell(row, entry.date); tbody.appendChild(row); }); ``` ]]>

T05 · Unauthorized Access and Privilege Escalation

Error
Location
FIREBASE_SETUP.md:47
Finding

Firebase Setup Grants Unauthenticated Write Access to Leaderboard Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
assets/rhythm-game-online.html:866
Finding

Remote Stored Cross-Site Scripting Through Online Leaderboard Records

Content
View full analysis
{ scores.unshift({ id: child.key, ...child.val() }); }); displayLeaderboard(scores); ``` The retrieved remote values are subsequently incorporated into an HTML string: ```javascript function displayLeaderboard(scores) { const content = document.getElementById('leaderboardContent'); if (scores.length === 0) { content.innerHTML = '
暂无记录,快来创造历史吧!
'; return; } let html = ` `; scores.forEach((entry, index) => { const rank = index + 1; const rankClass = rank <= 3 ? `rank-${rank}` : ''; const date = entry.date ? new Date(entry.date).toLocaleDateString() : '未知'; html += ` `; }); html += '
排名玩家分数连击难度时间
${rank}${escapeHtml(entry.playerName)}${entry.score.toLocaleString()}${entry.maxCombo}${entry.difficulty ? entry.difficulty.toUpperCase() : '-'}${date}
'; content.innerHTML = html; } ``` Only the player name is encoded: ```javascr ...[truncated 2439 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (22)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
- `assets/rhythm-game.html` - 完整的网页版游戏

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
- `assets/rhythm-game.html` - 完整的网页版游戏

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 185)May include surrounding context.

md
- `assets/rhythm-game.html` - 完整的网页版游戏

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document instructs users to deploy the game publicly and collect globally shared leaderboard data, but it does not clearly tell operators to present a privacy notice, obtain any needed consent, or disclose what player data is stored and exposed. In this context, player names, scores, timestamps, and cross-device visibility are explicitly retained and shared, so missing disclosure can create privacy/compliance risk and surprise users about public data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly describes adding a networked leaderboard using Firebase or a custom backend, including uploading score data, but it does not disclose that player data would be transmitted to third-party or external services. In a game skill, this is not inherently malicious, but omission of privacy and data-flow notice can mislead deployers and users about what information leaves the browser and where it is stored.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are broad recreational requests like wanting to play a rhythm game or test reaction speed, which can overlap with many general entertainment intents. This can cause the skill to activate when a user did not specifically request this game, creating unintended behavior and reducing user control over tool invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states that scores are saved locally and may be extended to online leaderboards, but it does not prominently warn users that gameplay data and chosen names may be stored in LocalStorage or transmitted to third-party services. This creates a privacy and transparency issue because users may unknowingly persist personal identifiers or share gameplay data externally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document sets lang="zh-CN" and all user-facing UI text and instructions are presented in Chinese, with no opt-in or language selection. Under the policy, forcing a specific language or locale without user choice is a natural-language policy violation unless the restriction is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The page loads third-party Firebase scripts from a remote origin and relies on a remote realtime database for functionality not essential to the core gameplay. This introduces supply-chain and data-exposure risk, since external code executes in the page and can affect users even when they only expect a local game.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The game is presented as a rhythm game with local play, but this implementation gates starting the game on Firebase initialization and sends player data to a remote backend. That expands the skill from local gameplay into networked data collection without clear necessity or transparency, increasing privacy and trust risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code uploads player names and detailed gameplay statistics to Firebase without presenting a prior privacy notice, retention policy, or explicit consent flow. In the context of a simple browser game, this is more dangerous because users reasonably expect local play and may not anticipate persistent remote storage of their identifiers and activity data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document declares lang="zh-CN", and the visible UI text is presented in Chinese throughout, which effectively fixes the skill to a specific language/locale. There is no indication that this locale restriction is optional, user-selected, or justified as a region-specific tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

这是一个 markdown 文件,适用 SQP-2 的文档审查标准。该段说明会将玩家名、分数、难度、时间戳等信息通过后端 API 存储和提交,但没有说明会上传数据、数据用途、是否公开排名,或给用户任何隐私提醒。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Firebase/cloud leaderboard section describes moving player scores and identifiers off-device to third-party storage, but it does not instruct implementers to disclose this data transfer or obtain user consent. In a game context this can expose player names, scores, timestamps, and related metadata to external services, creating a privacy and transparency issue even if the code is otherwise functional.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The saveScoreOnline example uploads scoreData directly to a remote database without any user-facing warning that gameplay data will be transmitted and stored remotely. Because scoreData may include player names and performance statistics, this omission can lead to unexpected collection and retention of personal or pseudonymous data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The custom backend API and sample responses show submission, ranking lookup, and public leaderboard exposure of playerName and score data, but the documentation does not warn about handling, publication, or retention of that user data. In an online game this can unintentionally expose user identifiers and performance data to other users or operators without adequate transparency or privacy controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file forces a single language/locale experience through all user-facing instructional text, and there is no indication that Chinese is optional or required for a region-specific reason. The policy calls for flagging language or locale constraints when they are imposed without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. The document is entirely in Chinese and presents the skill interface and instructions only in that language, with no indication that this is optional, region-specific, or accompanied by an alternative language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Most user-facing instructions and invocation examples are in Chinese, and the sample dialogue assumes Chinese-language interaction. Because no opt-in or alternative language behavior is described, the skill appears to impose a language/locale preference without an explicit user choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The interface advertises separate leaderboard scopes, and switchTab stores the selected tab, but loadLeaderboard always queries by score only and ignores currentTab. This is an intent/behavior divergence where the documented UI capability contradicts the actual implementation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This HTML file contains JavaScript code that saves the user's entered player name and gameplay statistics into browser localStorage, which is a write to persistent user data. While the save action is user-initiated, the file provides no visible warning, comment, or explanatory text that the name and score history will be stored locally on the device.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

SQP-3 适用于所有文件类型,并要求检查语言/地区策略违规。该文档完全以中文编写,未见任何用户语言选择、可切换语言说明,或对中文限定的合理场景说明,可能构成默认强制特定语言。

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
FIREBASE_SETUP.md:77