Back to skill

Security audit

opprime-world-key

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-related to Opprime World onboarding, but it performs under-disclosed install-time network access, stores authentication tokens in plaintext, and can modify nearby local runtime/protocol state.

Install only if you are comfortable with the skill contacting opprimeworld.com during installation and use, sending chosen names/owner details/mail content to that service, and saving a returned token locally in plaintext. Avoid real names, secrets, credentials, or sensitive business content in registration fields or mailbox messages, and treat identity.json as a credential file.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation expands the skill from identity/mail onboarding into mining, wallet, shop, reporting, and other operational functions not reflected in the stated purpose. Broader-than-declared functionality increases the chance of unexpected network actions, financial interactions, or automation being invoked under a misleadingly narrow description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The install hook performs unsolicited network access to opprimeworld.com and writes a snapshot file to /tmp during installation, which exceeds a minimal 'key/identity enablement' action and creates side effects at install time. Even though the fetched data appears to be public stats rather than secrets, silent external communication and filesystem writes during install weaken user control, create privacy concerns, and expand the attack surface if the remote endpoint or local environment is compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script performs side effects beyond the stated registration purpose by invoking local protocol and runtime initialization tools after remote account creation. This expands the trust boundary and can unexpectedly alter the host environment, creating persistence-like state or service registrations that a user would not reasonably expect from a simple onboarding script.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script modifies a separate population registry outside its declared onboarding scope, writing to a relative path in another part of the workspace. This is dangerous because it changes unrelated application state without explicit consent, which can corrupt data, interfere with other tools, or be abused to manipulate shared metadata on systems where the skill is installed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The registration step instructs users to POST identifying data such as a chosen name and owner name to a third-party service, but it does not provide a clear privacy warning or explain retention, sharing, or on-chain implications. In the context of a persistent identity/metaverse system, this can cause users or agents to disclose personal or linkable identity data without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The mailbox instructions encourage sending and retrieving messages through a remote service without a prominent warning that message contents, recipient/sender metadata, and associated identifiers may be permanently recorded or publicly exposed. Although the text later mentions mail is recorded on-chain, it is not presented as a strong privacy/security warning at the point of action, which can mislead users into sharing sensitive information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to transmit DID and authentication token headers to remote endpoints without prominent security guidance on token secrecy, endpoint trust, reuse risk, or leakage via logs/history. Exposing bearer-like credentials in shell examples can lead to account takeover or unauthorized profile actions if copied into shared terminals, logs, or agent traces.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation encourages sending email before giving an upfront, prominent warning that message contents become immutable on-chain records. Users or agents may disclose personal, confidential, or regulated information believing this is ordinary messaging, creating irreversible privacy and compliance harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The install hook makes outbound HTTPS requests during installation without any prior user-facing notice or opt-in. Even if no obvious secrets are sent in the request body, installation-triggered network traffic can leak metadata such as IP address, installation timing, and environment-driven behavior to a third party, and normalizes hidden data transmission from package hooks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script sends the fairy's mail address as a query parameter to a remote endpoint without any consent prompt, minimization, or validation of the destination. Because the base URL is taken from identity data, a modified identity file could redirect requests to an attacker-controlled host and leak the mailbox identifier or enable internal network probing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script transmits user-supplied identity information, including owner email, fairy name, and owner name, to a remote API without an explicit privacy notice or consent step. In the context of an agent skill, this is more dangerous because users may run it locally assuming it only configures the skill, not that it sends personal data to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script stores the returned DID and especially the token in a local identity.json file under a predictable path, without warning the user or restricting file permissions. Persisting credentials in plaintext can allow other local users, backup systems, logs, or later processes to recover and misuse the token for unauthorized access or impersonation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.