Back to skill

Security audit

Cyber Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill fits its game-agent purpose, but its default setup can run mutable remote code and expose a local control API too broadly.

Review before installing. Prefer a pinned image digest or verified release binary, bind the agent API to 127.0.0.1, avoid the plaintext public test server for real use, and understand that the agent stores an auth token and persistent game data locally.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
DEPLOYMENT.md:141
Finding

Unverified Remote Executables Are Downloaded and Installed

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:27
Finding

Mutable Container Image Is Pulled and Executed by the Quick-Start Command

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:27
Finding

Quick-Start Command Publishes a Sensitive Control API on All Interfaces

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
DEPLOYMENT.md:21
Finding

Public Game Server Is Recommended Over Plaintext WebSocket Transport

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (21)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · DEPLOYMENT.md (reported line 349)May include surrounding context.

3. 如果配置损坏,删除后重新注册

⚠️ 注意:agent.yaml 中包含 auth_token,删除后需重新注册角色

rm -rf ~/.cyber-jianghu/config/agent.yaml docker restart cyber-jianghu-agent

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · DEPLOYMENT.md (reported line 349)May include surrounding context.

3. 如果配置损坏,删除后重新注册

⚠️ 注意:agent.yaml 中包含 auth_token,删除后需重新注册角色

rm -rf ~/.cyber-jianghu/config/agent.yaml docker restart cyber-jianghu-agent

text

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 145)May include surrounding context.

md
install -m 755 cyber-jianghu-agent ~/.local/bin/

# 2. 创建 systemd 服务
mkdir -p ~/.config/systemd/user
cat > ~/.config/systemd/user/cyber-jianghu-agent.service << 'EOF'
[Unit]
Description=Cyber-Jianghu Agent

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 171)May include surrounding context.

md
# 4. 启用并启动
systemctl --user daemon-reload
systemctl --user enable --now cyber-jianghu-agent

# 5. 启用 linger(使服务在登出后继续运行)
sudo loginctl enable-linger $USER

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 174)May include surrounding context.

systemctl --user enable --now cyber-jianghu-agent

5. 启用 linger(使服务在登出后继续运行)

sudo loginctl enable-linger $USER

text

#### macOS (launchd)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 185)May include surrounding context.

md
install -m 755 cyber-jianghu-agent ~/.local/bin/

# 2. 创建数据目录
mkdir -p ~/.cyber-jianghu/config ~/.cyber-jianghu/data

# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 187)May include surrounding context.

md
# 2. 创建数据目录
mkdir -p ~/.cyber-jianghu/config ~/.cyber-jianghu/data

# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 188)May include surrounding context.

md
# 2. 创建数据目录
mkdir -p ~/.cyber-jianghu/config ~/.cyber-jianghu/data

# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 190)May include surrounding context.

md
# 2. 创建数据目录
mkdir -p ~/.cyber-jianghu/config ~/.cyber-jianghu/data

# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 191)May include surrounding context.

md
# 2. 创建数据目录
mkdir -p ~/.cyber-jianghu/config ~/.cyber-jianghu/data

# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 226)May include surrounding context.

md
# 2. 创建数据目录
mkdir -p ~/.cyber-jianghu/config ~/.cyber-jianghu/data

# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 230)May include surrounding context.

md
# 2. 创建数据目录
mkdir -p ~/.cyber-jianghu/config ~/.cyber-jianghu/data

# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 190)May include surrounding context.

md
# 3. 创建 launchd plist
cat > ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 230)May include surrounding context.

EOF

4. 加载服务

launchctl load ~/Library/LaunchAgents/com.8kugames.cyber-jianghu-agent.plist

text

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 324)May include surrounding context.

md
# 2. 如果配置丢失或令牌无效,需要重新注册
# 调用注册接口(首次运行时会自动注册)
curl -X POST http://localhost:23340/api/v1/character/register \
  -H "Content-Type: application/json" \
  -d '{"name": "你的角色名", ...}'

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 345)May include surrounding context.

md
docker logs cyber-jianghu-agent

# 2. 检查持久化数据
ls -la ~/.cyber-jianghu/config/ ~/.cyber-jianghu/data/

# 3. 如果配置损坏,删除后重新注册
# ⚠️ 注意:agent.yaml 中包含 auth_token,删除后需重新注册角色

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill text is written as a direct instruction to the agent in Chinese and frames the agent as the user's sole interface to the world, but it does not state that Chinese is optional or user-selectable. This creates a natural-language policy issue because the skill effectively imposes a specific language/locale without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The documentation tells users to run a container from ghcr.io/8kugames/cyber-jianghu-agent:latest, which is a mutable tag rather than a pinned version or digest. This creates a supply-chain risk: a future image update, compromised registry account, or malicious retag could cause users to deploy unexpected code with network exposure on port 23340.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.