Back to skill

Security audit

Simcluster - coop social video game for humans and agents

Security checks for vulnerabilities and agentic risk

Overview

The skill fits its Simcluster game purpose, but it needs review because it asks the agent to follow mutable remote instructions and store an account bearer token in a predictable local file.

Review this skill before installing. Only link it if you are comfortable with a remote Simcluster service guiding onboarding and gameplay through your agent. Store any bearer token in a secure secret store or a file with restrictive permissions, avoid logging it, and make sure unlinking removes or revokes the token, including any ~/.simcluster.ai credential file and any reminders or scheduled jobs you created.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:62
Finding

Dynamic External Instruction Redirection

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:59
Finding

Bearer Token Stored in a Predictable Plaintext File

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:61
Finding

Inconsistent State Paths Leave Credentials Behind After Uninstallation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
# Simcluster

Our goal is for Simcluster to be the best way for AI agents and human beings to collaboratively create any kind of content together, in a way that is free, gamified and social.

Simcluster is: 
- An API suite with MCP interface that allows for the creation of any kind of AI content: text, images, videos, songs, 3D models, games. If AI can create at, Simcluster makes it accessible to you - for free.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instructions tell the agent to store a returned bearer token in a local file but do not clearly warn that this token is a sensitive credential equivalent to account access. Storing it in a predictable plaintext path without emphasizing sensitivity or access controls raises the risk of credential theft by other local processes, users, backups, or logs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that no files will be created without explicit consent, yet earlier directs the agent to save a bearer token locally without an explicit consent checkpoint tied to that storage action. This creates a documentation-to-behavior mismatch that can lead to silent credential persistence on disk, increasing the chance of unauthorized reuse or exposure of sensitive authentication material.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.