Back to skill

Security audit

futbol-libre-hoy

Security checks for vulnerabilities and agentic risk

Overview

The skill has a simple sports-score purpose, but it tells agents to run or install an unpinned third-party package, so users cannot know what code will execute later.

Review this skill before installing. Its visible purpose is coherent, but only use it in a constrained environment or after pinning and reviewing the `futbol-libre-hoy` package version you intend to run. Avoid using it where the agent has access to sensitive files, credentials, or writable production workspaces.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Third-Party Package Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:13-16 and SKILL.md:21-22
Vulnerability Type: Unpinned npm and PyPI dependencies
Risk Level: Medium

Vulnerable Code

bash
npx futbol-libre-hoy
npx futbol-libre-hoy --live
npx futbol-libre-hoy --date YYYY-MM-DD
npx futbol-libre-hoy --json
bash
pip install futbol-libre-hoy
futbol-libre-hoy --live

Technical Analysis

The skill instructs the Agent to download and execute the futbol-libre-hoy package without specifying a reviewed version or verifying package integrity.

The npx commands may retrieve the current package release from the npm registry and execute its lifecycle or runtime code immediately. The Python alternative similarly installs the latest available PyPI release before executing it. The project does not contain the dependency's source code, a lockfile, integrity metadata, or hashes, so the package's effective behavior cannot be verified from the audited artifact.

This creates a supply-chain risk: a compromised maintainer account, malicious replacement release, or future compromised package version could cause attacker-controlled code to run with the permissions of the Agent's operating-system account.

No evidence establishes that the current external package is malicious. The vulnerability is the unsafe, unpinned trust and execution model.

Attack Path

  1. An attacker compromises the npm or PyPI package, its maintainer account, or a release process.
  2. The attacker publishes a malicious release under the expected package name.
  3. The Agent follows SKILL.md and invokes npx futbol-libre-hoy or installs the package using pip install futbol-libre-hoy.
  4. The package manager resolves the unpinned dependency to the attacker-controlled release.
  5. Package lifecycle hooks or runtime code execute locally with the Agent process's permissions.
  6. The malicious code can access resources available to that account and perform filesystem or network operations per ...[truncated 634 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npm and Python dependencies to exact, security-reviewed versions rather than resolving the latest release.
  2. For npm, commit a lockfile containing registry resolution and integrity metadata, and use a deterministic installation mechanism such as npm ci.
  3. Avoid implicit download-and-execute behavior through an unqualified npx command. Install a reviewed, pinned dependency first and invoke that controlled installation.
  4. For Python, use a locked requirements file with an exact version and cryptographic hashes, then install with hash verification enabled.
  5. Review the dependency source, package lifecycle scripts, transitive dependencies, and published artifacts before approving a version.
  6. Re-review and test dependency updates before changing the pinned version.
  7. Run the package in a sandbox with minimal filesystem access, no unnecessary credentials, and restricted outbound network access.
  8. Vendor the reviewed implementation when practical so the effective executable code remains available for audit.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill instructs use of npx futbol-libre-hoy without pinning an exact package version, which causes execution of whatever version is current in the registry at runtime. If the package is compromised, typo-squatted, transferred, or updated maliciously, users could execute attacker-controlled code from a trusted-looking skill path.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This command again relies on unpinned npx execution, here with the --live flag, so the risk is not the flag but the dynamic package resolution and code execution. An attacker who gains control over the package supply chain could deliver arbitrary code when a user requests live scores.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using npx futbol-libre-hoy --date YYYY-MM-DD still executes an unpinned remote package version. The skill context makes this moderately dangerous because it presents routine sports data retrieval as low-risk, which may reduce user caution while still granting code execution to an external package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The --json variant has the same underlying problem: unpinned npx execution permits supply-chain compromise to become code execution on the caller's system. Output format does not mitigate the risk because the vulnerability occurs before any JSON is produced.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The instruction says to use this skill when the user asks for today's football matches or live scores, but it does not define any narrower trigger scope, exclusions, or negative examples. This broad natural-language trigger could cause the skill to activate for generic sports questions without clarifying when it should not be used.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.