Back to skill

Security audit

Sports Betting Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill is not a backdoor, but it should be reviewed because it can give gambling recommendations from simulated or random data, stores analysis history locally, and auto-installs an unpinned dependency.

Install only if you understand it is a Chinese-language gambling-analysis MVP using simulated/random data, not real verified sports data. Do not rely on its betting percentages or recommendations for wagering. Review or disable local history/report saving if betting interests are sensitive, and pin dependencies before running the installer path.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/runner.sh:7
Finding

Automatic Installation of an Unpinned Runtime Dependency

Content
View full analysis
=1.21.0 ``` ### Technical Analysis The launcher automatically invokes `pip install numpy -q` during normal execution whenever the local virtual environment does not exist. This downloads and installs the latest compatible package selected by the active Python package index and local pip configuration. Neither the launcher nor `requirements.txt` specifies: - An exact reviewed package version - Package hashes - An explicitly trusted package index - A reproducible lock file - A separate, user-reviewed installation phase Python package installation can execute package build or installation logic with the privileges of the user running the Skill. The use of quiet mode also suppresses information that would otherwise help users inspect dependency resolution and installation failures. No evidence was found that the project intentionally references a malicious package. The risk arises from unsafe and non-reproducible dependency resolution. ### Attack Path 1. A user invokes `scripts/runner.sh`. 2. The expected `venv` directory is absent. 3. The script creates and activates a virtual environment. 4. The script contacts the package index configured for pip and resolves an uncontrolled compatible NumPy release. 5. If the selected package source or release is compromised, malicious installation logic executes with the invoking user's permissions. 6. The installed package can subsequently execute again when imported by `scripts/prediction_model.py`. Exploita ...[truncated 632 chars]
Remediation
View remediation
``` 2. Generate a hash-locked dependency file and require hash verification: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 3. Move dependency installation into an explicit setup step rather than performing it automatically during every first run. 4. Invoke pip through the selected interpreter to prevent executable ambiguity: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 5. Configure an explicitly trusted package index or an organization-controlled artifact repository. 6. Remove quiet mode so that users and automated logs can inspect the selected source, version, and installation errors. 7. Add automated dependency review and vulnerability scanning for every lock-file update. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/report_generator.py:363
Finding

Unrestricted Output Paths Permit File Writes Outside Intended Directories

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (32)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The function presents itself as determining whether a bet has value, but it actually returns a random result. In a betting-assistance context, fabricated or simulated outputs disguised as analytical judgments can materially mislead users into risky financial decisions based on false confidence.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The disclaimer says '本分析仅供参考,不构成投注建议', directly asserting that the output is not betting advice. However, other code paths generate structured 'betting_recommendation' content with actions such as '推荐投注' and concrete 'bet_percentage' values, which is active betting advice rather than mere neutral analysis.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README shows very broad natural-language invocation examples such as generic requests for betting recommendations and history lookup without documenting strict activation boundaries or confirmation requirements. In an agent environment, this can cause the skill to trigger on loosely related user text and provide gambling-oriented guidance unexpectedly, increasing the chance of unintended execution or policy-sensitive behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and heading/body content are presented in Chinese, and the usage examples and guidance continue in Chinese only. This indicates a language-specific skill experience without any opt-in, alternative language support, or explanation that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language description is written entirely in Chinese and presents the skill as a Chinese-language assistant, with no indication that users can choose another language or locale. This can violate language/locale policy requirements when a skill implicitly forces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON file stores user-facing report text almost entirely in Chinese, including match labels, explanations, and disclaimers. Because the file provides no indication that language selection is optional or region-specific, it suggests a fixed locale behavior that may violate language-choice policy.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The stored report presents predictive outcome text and a suggested betting percentage while also claiming it does not constitute betting advice. That contradiction can mislead users into treating the output as actionable wagering guidance, especially in a gambling-focused skill where users are likely to rely on apparent recommendations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This report contains a disclaimer saying the analysis is not betting advice, yet nearby content still includes a betting-oriented summary and risk framing tied to wagering decisions. In a betting assistant context, inconsistent messaging can materially influence user behavior and create compliance and consumer-protection risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The report for the football match uses Chinese for user-facing summary, explanation, recommendations, and disclaimer text, while no language preference mechanism or justification is present in the file. This indicates the skill may enforce a specific language regardless of user needs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The second stored report again mixes a 'not betting advice' disclaimer with prediction and bet-sizing language, creating a deceptive or at least confusing representation of the tool's purpose. Because the skill is explicitly about sports betting analysis, users may reasonably infer the system endorses wagering decisions despite the disclaimer.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The disclaimer appears alongside content that still operationalizes betting decisions through confidence, risk, and suggested stake information. This mismatch is dangerous because it can reduce user caution while preserving the persuasive effect of the recommendation, especially for higher-risk users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This report again contains user-facing narrative text only in Chinese, including analytical explanation and warnings. Repeated use across entries strengthens the indication of a hard-coded locale choice rather than user-selected output.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This third report continues the same contradiction: it says the output is only for reference while still presenting betting-related recommendation structure. In a skill centered on wagering analysis, such contradictions are more dangerous because the domain itself primes users to act on even weakly phrased advice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The stored disclaimer conflicts with the broader report structure that includes predictive and stake-related guidance. Even if the immediate recommendation is to abstain, the presence of betting-specific recommendation fields can still constitute actionable gambling guidance and undermine the disclaimer.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description and command-line user-facing strings are written in Chinese, which imposes a specific language/locale on users without any opt-in or alternative. This is a natural-language policy concern because the skill does not indicate that it is region- or language-specific nor provide a language selection.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The code auto-creates a local configuration file when one does not exist, introducing persistent side effects beyond pure analysis behavior. While not directly exploitable as code execution, it can surprise users, create undeclared files, and normalize disk writes in a tool whose stated purpose is only analysis and recommendations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script persists full analysis reports with timestamps to a local history file without any consent or notice. This creates an unnecessary privacy and data-retention risk because user interests, betting behavior, or match selections can be stored on disk and later accessed by other local users or processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Writing betting analysis history to disk without warning or consent is a genuine privacy and transparency issue. Even if the data is local-only, stored reports can reveal sensitive behavioral patterns and may be exposed on shared systems or through backups.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The 'today recommendations' feature claims to retrieve current recommendations, but it only returns hard-coded mock picks. In this skill's context, users may interpret these as real data-driven betting suggestions, creating deception risk and potentially influencing financial behavior with fabricated content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code file contains natural-language documentation entirely in Chinese, including the module description and class docstring, with no indication that language selection is optional. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The save_match_data method performs a file write by serializing match data to a JSON file. Although the docstring says '保存比赛数据', there is no user-facing confirmation, logging, or clearer disclosure about where data is stored and that persistence occurs, which is relevant for user data handling.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This finding is valid because the module presents itself as performing probability prediction and confidence assessment for betting analysis, yet _predict_total and _predict_over_under generate outputs using random.uniform rather than model inputs or calibrated statistical logic. In a sports-betting assistant, this can mislead users into treating arbitrary numbers as evidence-based predictions, causing harmful decision-making and undermining trust in the system's outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code’s natural-language content, including the module description and all generated report text, is written exclusively in Chinese with no indication that the user can choose another language. That creates a language/locale policy issue because the skill appears to impose a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a sports betting analysis assistant that provides data analysis, probability prediction, and betting suggestions, but this module also writes generated reports and raw JSON outputs into a local reports directory. Persistent file output is not an obvious requirement of the stated assistant behavior and extends the implementation from analysis/presentation into local storage side effects.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.exposed_secret_literal, suspicious.insecure_tls_verification (+1 more)

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/_core/arrayprint.py:1568

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/_core/tests/test_arrayprint.py:339

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/_core/tests/test_dtype.py:1070

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/_core/tests/test_multiarray.py:1665

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/_core/tests/test_records.py:170

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/_core/tests/test_scalarmath.py:618

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/_core/tests/test_simd.py:244

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/_core/tests/test_umath_accuracy.py:77

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/_core/tests/test_umath.py:512

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/f2py/auxfuncs.py:632

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/f2py/capi_maps.py:159

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/f2py/crackfortran.py:1329

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/random/tests/test_extending.py:111

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/testing/_private/extbuild.py:78

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/tests/test_lazyloading.py:26

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/tests/test_public_api.py:405

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/numpy/typing/tests/test_typing.py:205

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/pip/_vendor/distlib/wheel.py:131

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/pip/_vendor/pygments/formatters/__init__.py:91

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/pip/_vendor/pyparsing/results.py:57

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
venv/lib/python3.12/site-packages/pip/_vendor/typing_extensions.py:1251

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
venv/lib/python3.12/site-packages/pip/_internal/network/auth.py:93

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
venv/lib/python3.12/site-packages/pip/_vendor/requests/adapters.py:214

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
venv/lib/python3.12/site-packages/pip/_vendor/requests/sessions.py:323

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
venv/lib/python3.12/site-packages/pip/_vendor/urllib3/connection.py:423

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
venv/lib/python3.12/site-packages/pip/_vendor/urllib3/connectionpool.py:988

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
venv/lib/python3.12/site-packages/pip/_vendor/urllib3/contrib/_securetransport/low_level.py:231

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
venv/lib/python3.12/site-packages/pip/_vendor/urllib3/contrib/socks.py:102

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/lib/python3.12/site-packages/numpy/_core/multiarray.py:112

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/lib/python3.12/site-packages/numpy/_core/tests/test_overrides.py:294

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/lib/python3.12/site-packages/numpy/lib/_ufunclike_impl.py:16

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/lib/python3.12/site-packages/pip/_internal/network/session.py:304

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/lib/python3.12/site-packages/pip/_vendor/distlib/wheel.py:183

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/lib/python3.12/site-packages/pip/_vendor/truststore/_macos.py:353

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/lib/python3.12/site-packages/pip/_vendor/truststore/_windows.py:443

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/lib/python3.12/site-packages/pip/_vendor/urllib3/connection.py:454

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/lib/python3.12/site-packages/pip/_vendor/urllib3/contrib/pyopenssl.py:113

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/lib/python3.12/site-packages/pip/_vendor/urllib3/contrib/securetransport.py:795

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
venv/lib/python3.12/site-packages/pip/_vendor/urllib3/util/ssl_.py:137

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/lib/python3.12/site-packages/numpy/_core/strings.py:570

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/lib/python3.12/site-packages/numpy/_core/tests/test_arrayprint.py:332

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/lib/python3.12/site-packages/numpy/_core/tests/test_defchararray.py:820

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/lib/python3.12/site-packages/numpy/_core/tests/test_longdouble.py:360

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/lib/python3.12/site-packages/numpy/_core/tests/test_multiarray.py:4628

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/lib/python3.12/site-packages/numpy/_core/tests/test_regression.py:2573

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/lib/python3.12/site-packages/numpy/lib/tests/test_format.py:573

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/lib/python3.12/site-packages/numpy/lib/tests/test_io.py:707

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
venv/lib/python3.12/site-packages/numpy/random/tests/test_generator_mt19937.py:972