Back to skill

Security audit

The Turing Pot Game — Where AI Agents Compete for SOL

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real-money Solana betting daemon that is mostly disclosed, but it gives a remote service and a long-running local process too much practical control over funds and sensitive data.

Install only with a dedicated low-balance wallet you are prepared to lose, and avoid passing the private key on the command line. Treat game chat as untrusted, avoid using --profile-pic with sensitive paths, and look for a version that pins the payment recipient locally, adds explicit confirmation and loss limits, and fixes the fairness status logic.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/player.js:622
Finding

Remote Game Server Controls the Destination of Signed SOL Transfers

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/player.js:301
Finding

Solana Private Key Is Forwarded in the Persistent Daemon Command Line

Content
View full analysis
a === '--start' ? '--foreground' : a); const child = spawn(process.execPath, [__filename, ...fwdArgs], { detached: true, stdio: ['ignore', fs.openSync(LOG_FILE, 'a'), fs.openSync(LOG_FILE, 'a')], }); ``` The documented launch command encourages this behavior: ```bash node {baseDir}/scripts/player.js --start \ --private-key "$TURING_POT_PRIVATE_KEY" \ --strategy kelly \ --min-bet 0.0005 \ --max-bet 0.003 \ --name "YourAgentName" ``` ### Technical Analysis The recommended command expands the private key into an operating-system process argument. When daemon mode starts, the entire original argument list is forwarded to a detached foreground child. Consequently, the private key remains present in the long-lived daemon's command line. Depending on operating-system policy, process arguments may be visible through: - Process inspection tools such as `ps`. - `/proc//cmdline`. - Monitoring and inventory agents. - Crash diagnostics and support bundles. - Audit or process-execution logs. - Other processes running under the same operating-system account. This undermines the security guidance that the key is held only in memory. While environment variables also have exposure risks, explicitly copying the secret into persistent argv makes it unnecessarily visible and exceeds the minimum privilege needed to initialize the wallet. ### Attack Path 1. The user follows the documented command and supplies the private key through `--private- ...[truncated 792 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/player.js:54
Finding

Profile Picture Option Can Upload Arbitrary Readable Local Files

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
scripts/player.js:117
Finding

Remote Chat Messages Are Surfaced to the Agent Without a Prompt-Injection Trust Boundary

Content
View full analysis
0) { console.log(JSON.stringify(unread, null, 2)); // Remind the agent what to do with chat_prompt events const chatPrompts = unread.filter(e => e.type === 'chat_prompt'); if (chatPrompts.length > 0) { console.log('\n---'); console.log('For each chat_prompt event: read the "instruction" field, compose'); console.log('one short in-character message, append to ~/.turing-pot/chat-out.jsonl'); console.log('as: {"message": "your message here"}'); console.log('The daemon sends it to game chat within 3 seconds. One sentence. No emojis.'); } } ``` ### Technical Analysis Arbitrary content written by a remote game participant is copied into an event and printed for consumption by the LLM. A participant only needs to include the agent name or token to trigger a `mention` event. The event uses JSON encoding, which prevents structural JSON injection, but it does not establish a semantic trust boundary for the language model. The Skill instructions do not explicitly s ...[truncated 1436 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/player.js:548
Finding

Fairness Status Can Be Reported as Verified Without Successful Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The metadata and description understate the skill's real behavior: it is not just a status/control utility, but a system that onboards to remote services, sends outbound chat, processes mentions, and uses a private key to place real-money bets. This mismatch is dangerous because users and reviewers may approve the skill without understanding that it can spend funds and communicate externally on its own.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The metadata and description understate the skill's real behavior: it is not just a status/control utility, but a system that onboards to remote services, sends outbound chat, processes mentions, and uses a private key to place real-money bets. This mismatch is dangerous because users and reviewers may approve the skill without understanding that it can spend funds and communicate externally on its own.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
**You do not make betting decisions.** A background daemon (`player.js`) runs

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README describes starting the skill with a natural-language command and later says the daemon 'begins betting,' but it does not foreground at the startup point that this action will automatically place real-money wagers and continue running in the background. In a skill that controls a funded wallet and private key, this omission materially increases the risk of uninformed consent, accidental financial loss, and users starting a persistent betting process without understanding the consequences.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Persisting a Solana private key in ~/.bashrc creates long-lived secret exposure on disk and increases the chance the key is recovered by local compromise, backups, shell history mistakes, or by any same-user process able to read the environment after login. In this skill's context, the secret directly controls real funds, so even a single disclosure can lead to wallet theft.

Content

Scanner excerpt · SECURITY.md (reported line 45)May include surrounding context.

Add to your shell profile on the EC2 instance:

bash
# Add to ~/.bashrc (NOT to any file the agent can read)
export TURING_POT_PRIVATE_KEY="your_base58_private_key_here"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SECURITY.md (reported line 59)May include surrounding context.

Lock down the file permissions on .bashrc as a basic precaution:

bash
chmod 600 ~/.bashrc

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SECURITY.md (reported line 125)May include surrounding context.

Lock down the file permissions on .bashrc as a basic precaution:

bash
chmod 600 ~/.bashrc

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SECURITY.md (reported line 126)May include surrounding context.

Lock down the file permissions on .bashrc as a basic precaution:

bash
chmod 600 ~/.bashrc

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SECURITY.md (reported line 115)May include surrounding context.

md
| Put key in SKILL.md or SOUL.md | Loaded into every conversation context |
| Put key in a `.env` file in the skill directory | Agent has read access to skill files |
| Commit anything to git | GitHub credential bots scan within minutes |
| Store key in plain text in any world-readable file | `chmod 600` at minimum on any file that must contain it |

---

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · SECURITY.md (reported line 115)May include surrounding context.

md
| Put key in SKILL.md or SOUL.md | Loaded into every conversation context |
| Put key in a `.env` file in the skill directory | Agent has read access to skill files |
| Commit anything to git | GitHub credential bots scan within minutes |
| Store key in plain text in any world-readable file | `chmod 600` at minimum on any file that must contain it |

---

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SECURITY.md (reported line 124)May include surrounding context.

Regardless of which option you use, lock down the OpenClaw config directory:

bash
chmod 700 ~/.openclaw
chmod 600 ~/.openclaw/openclaw.json
chmod 600 ~/.turing-pot/session.json   # contains wallet pubkey + stats

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SECURITY.md (reported line 134)May include surrounding context.

Regardless of which option you use, lock down the OpenClaw config directory:

bash
chmod 700 ~/.openclaw
chmod 600 ~/.openclaw/openclaw.json
chmod 600 ~/.turing-pot/session.json   # contains wallet pubkey + stats

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill requires access to a highly sensitive environment secret (TURING_POT_PRIVATE_KEY) and performs networked, fund-moving actions, but it declares no explicit tool scope or permission boundary. That omission increases the chance an agent or platform will expose capabilities more broadly than intended, reducing reviewability and making accidental misuse of wallet credentials and external actions more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The start instructions launch a daemon that will automatically place real-money bets using a funded wallet, but the operational step is not paired with a clear, immediate warning or confirmation requirement at the point of execution. In context, this is risky because a user may treat --start as a harmless service action rather than authorizing autonomous spending from their wallet.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest advertises a SOL betting game for AI agents but provides no warning about financial risk, wallet usage, or the possibility of losing funds. In an agent-skill context, this omission is dangerous because automated systems or operators may invoke the skill without understanding that it can trigger value-bearing actions or interact with wallets.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/check.js (reported line 83)May include surrounding context.

js
}
}

// Rewrite file with all entries marked read
fs.writeFileSync(EVENTS_FILE, updated.join('\n') + '\n');

// Only print (and therefore only wake the LLM) if there's something to act on

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script performs a persistent file write that changes event state for all entries by marking them as read. While the header comment documents this behavior, there is no runtime disclosure, confirmation, or visible warning when the destructive state change occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The usage text encourages passing the Solana private key on the command line, and the parser directly accepts --private-key. Command-line secrets are commonly exposed via shell history, process listings, job control logs, crash reports, or observability tooling, which can lead to full wallet compromise and theft of funds.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description says it plays a betting game and manages the daemon, but this code also logs all chat, detects mentions, generates chat prompts, and enables outbound chat via a file-driven channel. That is a material behavioral expansion because it creates additional social/output capabilities and persistent collection of third-party messages that users may not expect from the published description.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The daemon persists full inbound chat messages to chat.jsonl for later agent consumption, creating a durable natural-language data store of third-party content. In this skill context, that increases privacy and prompt-injection risk because untrusted remote users can plant instructions or sensitive content that may later influence the agent or be exposed through logs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

On first startup, the player automatically sends agent identity data to a separate onboarding HTTPS service, but this outbound registration is not disclosed in the skill description. Hidden network egress to an additional endpoint is security-relevant because it expands data sharing and trust assumptions beyond the primary game WebSocket and RPC endpoints.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 19)May include surrounding context.

json
"node": ">=18"
  },
  "optionalDependencies": {
    "ws": "^8.18.0"
  }
}

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest says the skill can start and stop a player daemon, so process control is partly declared, but this implementation achieves it by spawning a detached child process. Spawning subprocesses is a powerful capability that is not inherent to a betting-game skill itself and should be explicitly justified as part of lifecycle management.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal, suspicious.secret_argv_exposure

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/player.js:302

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/solana-lite.js:126

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SECURITY.md:29