Back to skill

Security audit

Football Transfer Intel — Truth Meter & Rumour Tracker

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed football-transfer lookup integration that sends only relevant player or club search terms to its stated API service.

Install only if you are comfortable sending football player and club search terms, and for authenticated calls your RT_API_KEY, to Rising Transfers. Prefer using hot topics without an API key when possible, and avoid placing unrelated private information in transfer queries.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill explicitly sends user-supplied player and club queries to a third-party API endpoint. While this appears necessary for the advertised functionality and is transparently documented, it is still an external data transmission risk because user input and an API credential are sent off-platform to an external service.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
| Endpoint | Method | Data Sent | Purpose |
|----------|--------|-----------|---------|
| `https://api.risingtransfers.com/api/v1/intelligence/hot-topics` | GET | None | Trending football transfers (free, 0 credits) |
| `https://api.risingtransfers.com/api/v1/intelligence/transfer` | POST | `{ "name": "<player_name>" }` | Player transfer rumour detail (3 credits) |
| `https://api.risingtransfers.com/api/v1/intel/verify` | GET | `?q=<player>+to+<club>` | Truth Meter credibility score (1–5 credits) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This endpoint sends player-name query data to an external service via POST. Even though the content is low sensitivity in normal use and the skill claims not to send conversation history, any external transmission of user-provided content and use of a bearer-style API key introduces privacy, logging, and third-party trust risk.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
| Endpoint | Method | Data Sent | Purpose |
|----------|--------|-----------|---------|
| `https://api.risingtransfers.com/api/v1/intelligence/hot-topics` | GET | None | Trending football transfers (free, 0 credits) |
| `https://api.risingtransfers.com/api/v1/intelligence/transfer` | POST | `{ "name": "<player_name>" }` | Player transfer rumour detail (3 credits) |
| `https://api.risingtransfers.com/api/v1/intel/verify` | GET | `?q=<player>+to+<club>` | Truth Meter credibility score (1–5 credits) |

No data is sent to any other endpoint. No conversation history is transmitted.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The verification endpoint transmits a composed transfer query string to a third-party service. In context this is expected behavior, but it remains a true data-exfiltration surface because user prompts are transformed into outbound requests, and users must trust the vendor's logging, retention, and handling claims.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
|----------|--------|-----------|---------|
| `https://api.risingtransfers.com/api/v1/intelligence/hot-topics` | GET | None | Trending football transfers (free, 0 credits) |
| `https://api.risingtransfers.com/api/v1/intelligence/transfer` | POST | `{ "name": "<player_name>" }` | Player transfer rumour detail (3 credits) |
| `https://api.risingtransfers.com/api/v1/intel/verify` | GET | `?q=<player>+to+<club>` | Truth Meter credibility score (1–5 credits) |

No data is sent to any other endpoint. No conversation history is transmitted.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The hot-topics mode performs an outbound network call to a third-party host and suggests optionally attaching the RT_API_KEY even though the endpoint is described as free. This increases unnecessary credential exposure because a key may be transmitted when no authentication is required.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

Call:

text
GET https://api.risingtransfers.com/api/v1/intelligence/hot-topics
Headers: X-RT-API-Key: <RT_API_KEY>   (optional for free topics)

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This instruction sends user-provided player/team data and the RT_API_KEY to an external API over the network. That is an intentional feature of the skill, but from a security-review perspective it is still a real outbound transmission channel with privacy and credential-handling implications.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

Call:

text
POST https://api.risingtransfers.com/api/v1/intelligence/transfer
Headers:
  X-RT-API-Key: <RT_API_KEY>
  Content-Type: application/json

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The truth-meter mode transmits a user-derived query string plus API credential to a remote service. Because the query is built from user input and sent externally, it creates a clear exfiltration path for prompt content related to the user's request, even if the expected data is only football-transfer terms.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

Call:

text
GET https://api.risingtransfers.com/api/v1/intel/verify?q=<player>+to+<club>
Headers: X-RT-API-Key: <RT_API_KEY>

Static analysis

No suspicious patterns detected.