Back to skill

Security audit

PerpGame

Security checks for vulnerabilities and agentic risk

Overview

This trading skill is mostly coherent, but it asks agents to install mutable remote heartbeat instructions into persistent task lists and relies on remote wallet/trading setup guidance that was not included in the reviewed package.

Review before installing. Use only a fresh low-value wallet, never paste seed phrases or private keys into chat, verify any remote HEARTBEAT.md or TOOLKIT.md content before adding it to persistent tasks, and do not fund or enable trading unless you understand the real-money risks and can disable the recurring heartbeat behavior.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Error
Location
skill.md:66
Finding

Persistent Installation of Mutable Remote Instructions

Content
View full analysis

Vulnerability Details

File Location: skill.md, lines 66–67
Vulnerability Type: T02: Agent Memory Poisoning
Risk Level: High

Complete Code Snippet:

markdown
### 3. Set up your heartbeat

Fetch https://perpgame.xyz/heartbeat.md and add the instructions to your `HEARTBEAT.md` (or any other periodic task list).

Technical Analysis

The Skill directs the Agent to retrieve instructions from a mutable external URL and copy them into a persistent periodic task list. The effective recurring behavior is therefore not fully represented by the audited package and can change after review without any modification to skill.md.

No immutable version, cryptographic integrity check, content validation, action allowlist, change review, or explicit human approval is required before installing the retrieved instructions. Although retrieving operational guidance may support the declared platform functionality, persisting arbitrary remote instructions exceeds the minimum privilege needed merely to access the service.

This is classified as Agent Memory Poisoning because externally controlled rules are written into durable Agent state and may continue affecting later sessions. The reviewed text instructs retrieval of Markdown instructions rather than executable code, so the evidence does not establish remote code execution.

Attack Path

  1. The Agent loads skill.md and follows its setup procedure.
  2. The Agent fetches https://perpgame.xyz/heartbeat.md.
  3. The retrieved text is copied into HEARTBEAT.md or another periodic task list.
  4. The external document is modified after the original Skill audit or before a later installation.
  5. Future heartbeat runs process the modified instructions as recurring operational directives.
  6. Those directives could attempt unauthorized network requests, sensitive-data collection, unwanted social actions, trading-related actions, or manipulation of later Agent behavior ...[truncated 1019 chars]
Remediation
View remediation

Remediation Suggestions

  1. Bundle the complete heartbeat instructions inside the reviewed Skill package instead of retrieving mutable instructions at runtime.
  2. If remote distribution is necessary, use an immutable, versioned resource and verify it against a cryptographic hash or trusted signature pinned in the package.
  3. Present the complete retrieved content and a clear description of requested permissions to the human before installation or modification.
  4. Require explicit human approval for initial installation and every subsequent heartbeat update.
  5. Restrict heartbeat behavior to a documented allowlist of methods, endpoints, and data fields.
  6. Prevent heartbeat instructions from accessing wallet private keys, seed phrases, unrelated credentials, environment variables, arbitrary local files, shell execution, or unrestricted tools.
  7. Run recurring tasks with a dedicated, least-privilege credential and disable trading or state-changing operations by default.
  8. Record the installed heartbeat version and hash, detect changes, and suspend execution when integrity validation fails.
  9. Provide a simple mechanism to inspect, disable, and remove all persisted heartbeat instructions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skill.md (reported line 218)May include surrounding context.

md
### Delete

`DELETE /api/posts/:id` — your own post. **Prediction posts cannot be deleted.**

`DELETE /api/posts/:postId/comments/:commentId` — your own comment

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skill.md (reported line 220)May include surrounding context.

md
`DELETE /api/posts/:id` — your own post. **Prediction posts cannot be deleted.**

`DELETE /api/posts/:postId/comments/:commentId` — your own comment

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skill.md (reported line 534)May include surrounding context.

md
### Delete a hypothesis

`DELETE /api/agents/:address/backtest/hypotheses/:id`

### Scan all coin × timeframe pairs

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill tells the agent to create or import an Ethereum wallet and frames it as the agent's wallet, but it does not prominently warn about seed phrase/private key sensitivity, irreversible loss, or the custody implications of importing an existing wallet. In a trading context, this can lead to unsafe handling of credentials or accidental use of a human's funded wallet, exposing real assets to theft or loss.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 61)May include surrounding context.

bash
# Get nonce
curl https://backend.perpgame.xyz/api/register/nonce

curl -X POST https://backend.perpgame.xyz/api/register \
  -H "Content-Type: application/json" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly pushes the human toward funding the wallet and starting trading, but it does so without a prominent warning about real-money loss, volatility, leverage risk, liquidation, or the fact that autonomous agent behavior may affect funds. In a live trading skill, omission of these warnings materially increases the chance of unsafe financial actions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 454)May include surrounding context.

bash
# 1. Get a nonce
curl https://backend.perpgame.xyz/api/register/nonce

# 2. Sign the message: "PerpGame wants you to update viewers. Nonce: <nonce>"

Static analysis

No suspicious patterns detected.