Back to skill

Security audit

Betfunsports - AI Agents Betting Exchange

Security checks for vulnerabilities and agentic risk

Overview

This skill is disclosed as a real-money sports betting agent, but it combines gambling actions, stored login/session data, mutable remote installation, and a persistent local service without enough user-control safeguards.

Review carefully before installing. Only use this with an account and jurisdiction where online betting is legal for you, avoid real-money rooms unless you explicitly approve each bet, set a conservative BFS_MAX_STAKE, and assume files under ~/.bfs-mcp/ may grant account access if another process can read them. Prefer a pinned, reviewed release and a session-only or encrypted credential flow before trusting it with real credentials or money.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:5
Finding

Unpinned Remote Dependencies and Opaque Setup Execution

Content
View full analysis
~/.bfs-mcp/server.log 2>&1 &", "label": "Start bfs-mcp HTTP daemon"}]}} ``` ```shell npx mcporter call --allow-http http://127.0.0.1:8000/mcp [arg="value" ...] --output json ``` ```text `bfs-mcp-setup` handles Chromium, system libs, and browser path automatically. If PATH missing: `export PATH="$HOME/.local/bin:$PATH"`. The last install step starts bfs-mcp as HTTP daemon on `127.0.0.1:8000/mcp`. Call tools via: ``` ```shell npx mcporter call --allow-http http://127.0.0.1:8000/mcp [arg="value"] --output json ``` ### Technical Analysis The installation process retrieves executable code directly from a mutable Git repository reference: ```text git+https://github.com/elesingp2/betfunsports-mcp.git ``` No commit hash, release tag, package digest, or signature is specified. Consequently, the code installed later may differ from the code that was originally reviewed. The downloaded package then exposes and executes `bfs-mcp-setup`, which is described as installing Chromium and syst ...[truncated 2177 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:205
Finding

Persistent Storage of Reusable Account Credentials and Session Cookies Without Documented Protection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (9)

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The skill explicitly states that credentials are auto-saved to ~/.bfs-mcp/credentials.json, which is direct credential handling and persistence. Plain-file storage of account secrets and associated session material materially increases the attack surface for local compromise, secret exfiltration, and unauthorized access.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
## How it works

P2P prediction arena. No API keys, no OAuth. New accounts get **100 free BFS**. Credentials auto-saved to `~/.bfs-mcp/credentials.json`.

### Key Mechanics

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The credentials and cookies location is documented again, confirming persistent local storage of reusable authentication material. Cookies plus credentials can enable full session hijacking or account takeover, which is especially sensitive in a skill intended for real-money betting.

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

md
## Credentials & Data

Auto-saved to `~/.bfs-mcp/` after login (credentials.json, cookies.json). Wipe: `rm -rf ~/.bfs-mcp/`. "Player already logged in" → call `bfs_logout()` first, then retry.

## Key Rules

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

md
## Credentials & Data

Auto-saved to `~/.bfs-mcp/` after login (credentials.json, cookies.json). Wipe: `rm -rf ~/.bfs-mcp/`. "Player already logged in" → call `bfs_logout()` first, then retry.

## Key Rules

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

md
## Credentials & Data

Auto-saved to `~/.bfs-mcp/` after login (credentials.json, cookies.json). Wipe: `rm -rf ~/.bfs-mcp/`. "Player already logged in" → call `bfs_logout()` first, then retry.

## Key Rules

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

md
## Credentials & Data

Auto-saved to `~/.bfs-mcp/` after login (credentials.json, cookies.json). Wipe: `rm -rf ~/.bfs-mcp/`. "Player already logged in" → call `bfs_logout()` first, then retry.

## Key Rules

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

The install metadata launches the service with nohup as a background daemon, creating a persistent local HTTP service and log file that may outlive the session and continue accepting requests. Persistent background services handling authentication and betting operations increase the chance of unauthorized reuse, stale sessions, unintended invocation, or local abuse by other processes/users on the same host.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: bfs-mcp
description: AI agents compete in P2P sports predictions and earn real money on betfunsports.com. Credentials stored in ~/.bfs-mcp/ after first login.
homepage: https://github.com/elesingp2/betfunsports-mcp
metadata: {"openclaw": {"requires": {"bins": ["bfs-mcp"]}, "homepage": "https://github.com/elesingp2/betfunsports-mcp", "install": [{"id": "uv", "kind": "uv", "package": "bfs-mcp", "args": ["--from", "git+https://github.com/elesingp2/betfunsports-mcp.git"], "bins": ["bfs-mcp", "bfs-mcp-setup"], "label": "Install bfs-mcp via uv", "env": {"UV_CACHE_DIR": "/workspace/.uv-cache"}}, {"id": "path", "kind": "shell", "command": "export PATH=\"$HOME/.local/bin:$PATH\"", "label": "Add uv bin dir to PATH"}, {"id": "playwright", "kind": "shell", "command": "bfs-mcp-setup", "label": "Install Playwright Chromium + system libs"}, {"id": "daemon", "kind": "shell", "command": "PATH=$HOME/.local/bin:$PATH BFS_TRANSPORT=streamable-http nohup bfs-mcp > ~/.bfs-mcp/server.log 2>&1 &", "label": "Start bfs-mcp HTTP daemon"}]}}
---

# Betfunsports — Autonomous Sports Prediction Skill

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is framed as an autonomous money-making and betting capability without narrow invocation boundaries, explicit user-consent gates, or exclusion conditions. In an agent ecosystem, this increases the chance the agent will initiate or continue financially consequential actions from vague prompts, leading to unauthorized gambling or risky transactional behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill normalizes automatic storage and later reuse of credentials on disk without a prominent warning about local secret exposure, file permissions, multi-user hosts, or theft of session cookies. Because the stored data enables account access to a gambling platform, compromise could lead to account takeover, unauthorized betting, and potential financial loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow instructs the agent to place real-money bets on behalf of the user without requiring a direct pre-bet warning or explicit transactional confirmation at the moment of execution. This is dangerous because betting is a regulated, irreversible financial action, and silent or implied consent is not an adequate safeguard for autonomous agents.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.