Back to skill

Security audit

Luckyball

Security checks for vulnerabilities and agentic risk

Overview

This lottery prediction skill is mostly about its stated task, but it asks the agent to read and modify persistent Claude memory files and use web search without clear user control.

Review before installing. The main risk is not malware; it is that the skill tells the agent to keep lottery prediction history in a hard-coded Claude memory location, update a memory index, and search the web for prior results. Use it only if you are comfortable with that persistence, and prefer changing it to a skill-owned local data file with explicit approval before any read, write, or web lookup.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:193
Finding

Unnecessary Access to Persistent Agent Memory and Cross-Project State

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description is entirely in Chinese and presents the skill as operating in that language, with no indication that users may choose another language or locale. Under the policy for natural-language violations, a skill should not implicitly force a specific language unless it offers opt-in or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest frames the skill as a local lottery-number predictor, but the body adds persistent local file writes and retrospective result reconciliation. This expands the skill's effective capabilities beyond what users or reviewers would reasonably expect, creating a transparency and trust problem and enabling unintended storage of user activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill describes persistent file writes and web lookups without a clear upfront warning or consent flow. Even if the stored/query data seems low sensitivity, undisclosed persistence and external access can violate user expectations and expose activity history or derived queries without informed consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documentation introduces WebSearch for lottery results even though the manifest only describes local prediction based on user-provided dates. Undisclosed outbound queries change the privacy and execution model, and could surprise users by transmitting contextual data externally.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a skill that takes a user-provided lottery draw date, computes Bazi, and generates recommended numbers. In practice, the code also loads historical Excel data, trains multiple machine-learning models, and fits an AR process before prediction, making the skill materially dependent on local dataset ingestion and model training rather than only date-based computation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The embedded main program hard-codes a specific local filesystem path, revealing developer environment details and creating undisclosed local file access behavior. While not directly exploitable for code execution, hard-coded local paths can leak sensitive host information, cause unintended file reads, and normalize hidden dependencies that are inconsistent with the declared skill behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Automatically updating a separate MEMORY.md index is not necessary for generating lottery predictions and increases the skill's write surface. Extra undocumented writes can create unwanted persistence, make behavior harder to audit, and normalize broader filesystem modification than the stated purpose requires.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This is a natural-language policy concern because the file presents its purpose and operational descriptions exclusively in a single language. There is no indication that Chinese is optional, user-selected, or required for a region-specific use case.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.