Back to skill

Security audit

Pg Game Monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate monitoring purpose, but its installer creates persistent services with insecure defaults, weak dependency integrity, and insufficient secret and network-access protections.

Review before installing. Run it only in a controlled internal environment after adding checksum/signature verification, pinning dependencies with hashes, setting unique Grafana credentials before startup, locking down ports with firewall/auth/TLS, storing secrets with strict permissions or a secret manager, and running services under dedicated least-privilege users.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T08 · Insecure Dependencies

Error
Location
references/files/monitor_install.sh:31
Finding

Downloaded Executables Are Installed Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/files/main.yml:17
Finding

Deployment Installs Mutable and Partially Unpinned Python Dependencies

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/files/main.yml:28
Finding

MySQL Password and Feishu Webhook Secret Are Stored Without Enforced Restrictive Permissions

Content
View full analysis
$BASE_DIR/feishu/webhook.env <
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/files/monitor_install.sh:303
Finding

Monitoring Services Are Started Without Authentication or Interface Restrictions

Content
View full analysis
/etc/systemd/system/prometheus.service < /etc/systemd/system/alertmanager.service <<'EOF' [Service] ExecStart=/opt/monitor/alertmanager/alertmanager \ --config.file=/opt/monitor/alertmanager/alertmanager.yml Restart=always EOF cat > /etc/systemd/system/pushgateway.service <<'EOF' [Service] ExecStart=/opt/monitor/pushgateway/pushgateway Restart=always EOF # ================= Start Services ================= systemctl daemon-reload systemctl enable prometheus alertmanager pushgateway grafana-server feishu systemctl start prometheus alertmanager pushgateway grafana-server feishu ``` ### Technical Analysis Prometheus, Alertmanager, and Pushgateway are started without explicit listen-address restrictions, authentication, TLS configuration, or firewall enforcement. The generated services consequently rely on their default listener behavior and the surrounding host/network configuration. Pushgateway is particularly sensitive because clients can submit metric groups. If its port is reachable by an untrusted party, that party may inject or replace monitoring data. Prometheus and Alertmanager may expose operational topology, host identifiers, game service names, database status, and alert state. The local Flask webhook is comparatively constrained because it explicitly binds to `127.0.0.1`; this finding applies to the other monitoring services started by the installer. ### Attack Path 1. The installer starts the monitoring services on a host whose firewall or security group allows access to ports 9090, 9091, or 9093. 2. An attacke ...[truncated 880 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/files/monitor_install.sh:13
Finding

Grafana Is Left With Documented Default Administrative Credentials

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (45)

Tainted flow: 'FEISHU_WEBHOOK_URL' from os.environ.get (line 22, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · references/files/webhook.py (reported line 110)May include surrounding context.

python
}
    }

    requests.post(FEISHU_WEBHOOK_URL, json=msg)
    return "ok"

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill advertises a comprehensive monitoring and deployment capability, but the file only describes components and example commands without showing the actual implementation artifacts. This mismatch can mislead users or higher-level agents into invoking the skill with expectations of safe, validated automation that does not actually exist, which is risky when deployment, monitoring, and alerting operations are involved.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents shell commands, network access, and use of environment variables, but does not declare any explicit tool scope such as permissions or allowed-tools. In an agent ecosystem, this can cause overbroad execution authority or make reviewers unable to verify what the skill is permitted to do, increasing the chance of unintended command execution or outbound requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The regex triggers are broad and can match many generic monitoring, Java, MySQL, Grafana, or Prometheus requests unrelated to this exact skill. In an agent environment, overbroad activation can cause the wrong skill to handle user requests, potentially leading to unintended shell commands, deployment guidance, or network actions in the wrong context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Ambiguous invocation phrases like viewing JVM metrics or querying MySQL status lack boundaries on host scope, environment, or whether the skill is advisory versus operational. This increases the chance of accidental invocation in unrelated contexts and may prompt an agent to perform actions against production monitoring systems without adequate confirmation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The documented curl command performs an outbound HTTP POST to a webhook endpoint, which is an external transmission action. While expected for alert testing, it can send data or trigger downstream notifications if used in a real environment, so the risk depends on whether the endpoint is production and whether test traffic is isolated.

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

飞书告警未收到

bash
curl -X POST "http://<webhook>:5000/webhook?level=warning" \
  -H "Content-Type: application/json" -d '{"alerts":[]}'
journalctl -u feishu -f

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file title and all operational instructions are written in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/faq.md (reported line 56)May include surrounding context.

md
### Q: Prometheus 页面看不到目标
**A**:
1. 检查 Pushgateway 在线:`curl http://<pushgateway>:9091/-/healthy`
2. 检查 Prometheus target:`http://<prometheus>:9090/targets`
3. 查看 Prometheus 日志:`journalctl -u prometheus -f`

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · references/files/game_agent.py (reported line 149)May include surrounding context.

python
# ================= JCMD Histogram Collection   =================
def collect_class_histo(game_dir, pid):
    try:
        out = subprocess.check_output(
            ["jcmd", str(pid), "GC.class_histogram"],
            stderr=subprocess.DEVNULL, timeout=15
        ).decode(errors="ignore")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · references/files/game_agent.py (reported line 189)May include surrounding context.

python
key = f"{HOSTNAME}_{game_dir}"

    try:
        out = subprocess.check_output(["jstat", "-gc", str(pid)]).decode().splitlines()[-1].split()

        # Memory
        s0u, s1u, eu = float(out[2]), float(out[3]), float(out[5])

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code pushes collected JVM and MySQL metrics to a remote Pushgateway, which is a network operation that transmits system data off-process. Although the module docstring mentions Prometheus Pushgateway, there is no confirmation prompt or stronger user-facing disclosure near the transmission path about what data is being sent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest describes a monitoring solution deployment, but this task uses a raw shell command to perform system-wide pip installation on the target host. While deployment itself is expected, invoking arbitrary shell-based package installation is a broader execution capability than the skill’s monitoring-focused purpose and is not specifically justified by the manifest text.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The playbook writes MySQL credentials in plaintext to /opt/game_monitor/env.conf, creating persistent at-rest exposure of sensitive secrets on disk. If file permissions are default or overly broad, any local user, backup process, log collection tool, or later compromise of the host could retrieve the database credentials and access MySQL.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script writes the Feishu webhook URL directly into /opt/monitor/feishu/webhook.env, leaving a sensitive integration secret on disk without setting restrictive permissions or warning the user at the point of creation. If local users or backup systems can read this file, an attacker could abuse the webhook to exfiltrate monitoring information or send spoofed alerts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The generated webhook service forwards hostnames, IP-derived data, service identifiers, and alert contents to an external Feishu endpoint, but the installer does not prominently disclose this outbound data flow during setup. In a production environment, this can unintentionally leak infrastructure metadata to a third-party service or to an incorrectly configured webhook destination.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/files/monitor_install.sh (reported line 326)May include surrounding context.

sh
# ================= Start Services =================
systemctl daemon-reload
systemctl enable prometheus alertmanager pushgateway grafana-server feishu
systemctl start prometheus alertmanager pushgateway grafana-server feishu

echo ""

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This YAML rule file contains user-facing natural-language alert text such as summaries and descriptions in Chinese only. Because the file does not offer a language choice or document a justified locale restriction, it may violate the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.