Back to skill

Security audit

TikiCow

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward TikiCow game API guide, but users should understand it gives an agent ongoing ability to change their game account once linked.

Install this only if you intend to let an agent operate your TikiCow account. Generate linking codes yourself, do not share the bearer token in logs or chat unnecessarily, and ask the agent to confirm before purchases, sales, listings, batch actions, or bot registration.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill activates for very broad intents like 'play, automate, or analyse' the game and then exposes many state-changing capabilities. Without tighter trigger constraints, an agent may invoke this skill in loosely related conversations and perform actions that spend resources, trade items, or alter game state without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This skill instructs the agent to redeem a human-provided linking code and store a bearer token for subsequent authenticated API use. Although this is expected functionality, it is still a sensitive external transmission and credential-handling flow: if mishandled, the token could grant ongoing control over the player's game account and enable unauthorized actions.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

  1. Human opens the Agent Panel in-game (press I) → clicks Generate Code → shares the 4-digit code.
  2. Agent redeems it within 10 minutes:
    text
    POST https://api.tikicow.com/v1/agent/redeem
    { "code": "1234" }
    
  3. Store the returned Bearer token. Use it as: Authorization: Bearer tc_<token>

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documents numerous write endpoints that can change game state, spend energy, consume inventory, and create or fill market listings, but it does not warn the user or require confirmation before executing them. In an agent setting, this creates a real risk of unintended purchases, sales, farming actions, or marketplace commitments based on ambiguous instructions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

md
- `GET /v1/agent/status` is the best polling endpoint — farm + market + weather + energy in one call.
- Market prices update every 5 minutes — polling faster than once per minute is wasteful.
- Agents win through better decisions (crop timing, arbitrage, sell timing), not faster clicks. The throttle stack makes speed-only strategies useless.
- Self-discovery: `GET https://api.tikicow.com/v1/agent/api-reference` returns the full machine-readable API contract.

## Links

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
- `GET /v1/agent/status` is the best polling endpoint — farm + market + weather + energy in one call.
- Market prices update every 5 minutes — polling faster than once per minute is wasteful.
- Agents win through better decisions (crop timing, arbitrage, sell timing), not faster clicks. The throttle stack makes speed-only strategies useless.
- Self-discovery: `GET https://api.tikicow.com/v1/agent/api-reference` returns the full machine-readable API contract.

## Links

Static analysis

No suspicious patterns detected.