Back to skill

Security audit

PetRPG

Security checks for vulnerabilities and agentic risk

Overview

This is a local pet game skill with some overstated multiplayer documentation, but the inspected artifacts do not implement network access, credential use, or hidden privileged behavior.

Install this only if you want the local pet game behavior. Treat the A2A multiplayer documentation as unimplemented and do not enable or build online features from this skill without a separate review of data sharing, peer authentication, and user consent. Be aware that achievement tracking may create or update a local data/achievements.json file if that manager is used.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior overstates the maturity and scope of the skill, including multiplayer A2A and fuller game mechanics that are not actually evidenced here. This mismatch can mislead users and agent platforms into enabling capabilities such as networking or persistent state based on inaccurate documentation, which is a trust and safety problem even if not direct code execution.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises executable Python scripts and implied file operations but does not declare any tool scope or permissions boundaries. In an agent environment, this can cause the host to grant broader-than-expected file access or leave operators unaware that local read/write capability is needed, increasing the chance of unintended filesystem access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes networked A2A registration and challenge flows without meaningfully warning that data may be transmitted to external agents or services. In agent ecosystems, undisclosed outbound communication can expose identifiers, pet state, metadata, or trigger interactions with untrusted remote parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The Security section explicitly downplays the risk of A2A networking by stating it is 'not security concern,' which can cause users or operators to ignore real privacy, abuse, and system-impact risks from remote interaction. Per the supplied instructions, language that dismisses security concerns is itself a red flag because it encourages unsafe deployment decisions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The enum defines distinct stages for EGG, BABY, TEEN, ADULT, and LEGENDARY, but PetStage.BABY is assigned the value "teen" instead of "baby". This directly contradicts the documented stage model in the module docstring and the surrounding code/comments that describe a baby stage, causing behavior to diverge from the stated pet progression intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.