Back to skill

Security audit

Rich Lottery

Security checks for vulnerabilities and agentic risk

Overview

This paid lottery skill is not outright malware, but it materially overstates its analysis and has weak payment and dependency controls that users should review before installing.

Review this carefully before installing or paying for it. The service presents itself as historical-data lottery analysis, but the inspected code appears to return simulated random picks. Treat any recommendations as entertainment only, and do not rely on the listed x402 payment flow as proof that the backend enforces payment correctly. The publisher should also pin dependencies and make the paid-service description match the implementation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
main.py:18
Finding

Payment Verification Bypass Through an Unvalidated x402 Header

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Flask Dependency Creates Non-Reproducible and Unsafe Deployments

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/lottery_analysis.py:13
Finding

Paid Historical Analysis Claims Are Implemented as Random Sampling from Hard-Coded Pools

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · main.py (reported line 35)May include surrounding context.

python
@app.route('/ssq')
def ssq():
    try:
        result = subprocess.run(
            [sys.executable, "scripts/lottery_analysis.py", "ssq"],
            capture_output=True,
            text=True,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes a lottery analysis and number recommendation skill, but the implementation invokes a separate Python process via subprocess.run to serve requests. Executing subprocesses is a powerful capability not inherently justified by the stated purpose, which could be implemented directly in-process.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · main.py (reported line 49)May include surrounding context.

python
@app.route('/dlt')
def dlt():
    try:
        result = subprocess.run(
            [sys.executable, "scripts/lottery_analysis.py", "dlt"],
            capture_output=True,
            text=True,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Like the /ssq route, the /dlt route launches a Python subprocess to perform analysis. For a skill presented as historical-data lottery recommendation, this process-execution capability exceeds the obvious functional need expressed in the manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description promises historical-data-based intelligent lottery analysis, but the implementation only uses hardcoded lists and random selection. This is a deceptive capability mismatch that can mislead users into trusting recommendations as data-driven when they are effectively arbitrary, creating integrity and consumer-trust risk rather than a traditional code-execution issue.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency specification uses an unpinned package name only, which allows different Flask versions to be installed over time. This creates a supply-chain and reproducibility risk because a vulnerable or breaking release could be resolved during installation without review.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
flask

Unverifiable Dependency: flask has 10 known advisory(ies) (CVE-2025-47278 (Flask uses fallback key instead of current signing key); CVE-2018-1000656 (Flask is vulnerable to Denial of Service via incorrect encoding of JSON data); CVE-2019-1010083 (Pallets Project Flask is vulnerable to Denial of Service via Unexpected memory u) +7 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Because Flask is not pinned to a specific version, it is impossible to verify from this manifest whether the installed release includes known security fixes. In practice this means deployments may resolve to a version affected by published Flask advisories, leaving the application exposed to known issues depending on runtime behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The inline comment explicitly says the logic is a 'historical data analysis simulation,' which conflicts with the external description implying genuine historical analysis. In this skill context, that discrepancy increases confidence that the feature is being overstated and may misrepresent its reliability to users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description uses Chinese-only text ("Rich彩票分析API - x402付费版本") and the endpoint descriptions are also Chinese-only, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking locale. This is a natural-language locale policy concern because the skill appears to enforce a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.