Back to skill

Security audit

Game Ops Monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent game-server monitoring guide, but it includes under-scoped persistent alerting and unsafe setup/transport guidance that users should review before installing.

Install only if you are comfortable granting the agent read access to broad Scouter game-server telemetry. Before enabling alerting, confirm the exact schedule, server scope, webhook destination, and how to disable the cronjob. Prefer HTTPS/authenticated Collector access, protect webhook URLs as secrets, and verify any downloaded Scouter release before extracting or running it.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T06 · System Persistence

Error
Location
references/alert-workflow.md:32
Finding

Persistent Scheduled Monitoring Task

Content
View full analysis
90%, send Feishu notification. Track cooldown to avoid duplicate alerts.", schedule="*/5 * * * *", name="Game Server Alert Monitor", skills=["game-ops-monitor"], deliver="origin") ``` ### Technical Analysis The documented setup creates a recurring Agent job that runs every five minutes and survives the interaction in which it was created. The task repeatedly queries all game servers and may initiate notifications through external webhook integrations. Scheduled monitoring is consistent with the optional alerting workflow, and the behavior is not hidden. Nevertheless, it exceeds the minimum privileges needed for the Skill's primary on-demand monitoring functionality. The instructions do not require explicit confirmation immediately before persistence is established, define an expiration time, restrict the job to a least-privilege identity, or provide a corresponding removal procedure. Because the scheduled prompt invokes the Skill again in future sessions, later changes to the Skill, its configuration, or its referenced notification behavior could affect an already-installed job. ### Attack Path 1. A user follows the alert setup instructions and creates the cron job. 2. The Agent platform stores the job across sessions. 3. Every five minutes, the job invokes `game-ops-monitor`. 4. The Skill queries operational data for all configured game servers. 5. When threshold conditions are met, results may be transmitted through the configured Feishu or DingTalk integration. 6. The process continues until an administrator manually identifies and removes the job. ### Impact Assessment The persistence grants recurri ...[truncated 493 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:382
Finding

Remote Archive Downloaded and Executed Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:81
Finding

Operational Monitoring Data Transmitted Over Plaintext HTTP

Content
View full analysis
with your Scouter Collector IP export SCOUTER_COLLECTOR_URL=http://:6188 ``` The value is subsequently used by monitoring requests such as: ```bash curl -s "http://${SCOUTER_COLLECTOR_URL}/scouter/v1/status" curl -s "http://${SCOUTER_COLLECTOR_URL}/scouter/v1/objects?type=${SCOUTER_OBJ_TYPE}" curl -s "http://${SCOUTER_COLLECTOR_URL}/scouter/v1/object/${objHash}/counter/tps" curl -s "http://${SCOUTER_COLLECTOR_URL}/scouter/v1/object/${objHash}/counter/active" curl -s "http://${SCOUTER_COLLECTOR_URL}/scouter/v1/object/${objHash}/counter/heap/used" curl -s "http://${SCOUTER_COLLECTOR_URL}/scouter/v1/object/${objHash}/counter/heap/max" ``` ### Technical Analysis The documented Collector configuration uses plaintext HTTP. No transport authentication, server certificate verification, or API authentication mechanism is documented. The responses contain operational information including object names, internal addresses, service state, throughput, active connection or user counts, and JVM heap capacity. An attacker with access to the relevant network path could passively observe these requests or actively modify Collector responses. The Skill validates `objHash` as hexadecimal before inserting it into later URLs, which reduces shell-injection exposure, but that validation does not protect the integrity or confidentiality of the metrics themselves. The examples also treat `SCOUTER_COLLECTOR_URL` inconsistently. It is configured as a complete URL beginning with `http://`, while several commands prepend another `http://`. This can produce malformed URLs such as `http://http://host:6188/...` and may encourage unsafe ad hoc corrections. ### Attack Path 1. The user configures the Collector endpoint with the documented plaintext HTTP URL. 2. The Skill ...[truncated 975 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document instructs operators to configure Feishu and DingTalk webhooks to send alert messages containing operational server telemetry, but it does not warn that TPS, heap, online-user counts, and server identifiers will be transmitted to third-party messaging platforms. This can create unintended data exposure, especially if users assume alerts remain internal or if the webhook destinations are not governed under the same security and retention controls as the monitoring system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The 'What to say' examples are exclusively in Chinese, which implicitly constrains users to a specific language. The document does not state that the skill is China-specific or provide alternative language options, so this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill includes bilingual trigger phrases and later mixes Chinese section headers with English labels in sample reports, but it does not state how the response language is selected. This can violate a language/locale policy when a skill implicitly chooses a language rather than offering or documenting a user-controlled preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The sample alert content for both Feishu and DingTalk is entirely in Chinese, which indicates a forced language choice in the skill's natural-language outputs. The file does not offer user opt-in for language selection or explain that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.