Back to skill

Security audit

chess-results

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chess-Results helper that queries public pages and can enter league results only through user-approved, credential-backed workflows.

Install only if you are comfortable giving the skill access to your Chess-Results account for result entry. Use the check workflow first, review the log carefully, and approve saving only when the filled report is correct, because saved results become visible to the league.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (67)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 7)May include surrounding context.

md
| Data | Where | Protection | Needed for |
|---|---|---|---|
| Chess-Results personal number + password | macOS Keychain (service `chess-results`), Windows Credential Manager or Linux Secret Service — or, where none exists, `~/.config/chess-results/credentials.json` | the system store; the file must be mode `0600` and the user's own, or it is refused | result entry only |
| Chess-Results session cookie | memory of the running process | never written to disk | result entry only |
| Public pages (searches, tournament pages) | `~/.cache/chess-results/pages` (or the host's plugin data folder) | plain cache of public HTML | queries |
| Club settings | `chess-results.json` in the project | no secrets | result entry only |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SETUP.md (reported line 32)May include surrounding context.

md
| Data | Where | Protection | Needed for |
|---|---|---|---|
| Chess-Results personal number + password | macOS Keychain (service `chess-results`), Windows Credential Manager or Linux Secret Service — or, where none exists, `~/.config/chess-results/credentials.json` | the system store; the file must be mode `0600` and the user's own, or it is refused | result entry only |
| Chess-Results session cookie | memory of the running process | never written to disk | result entry only |
| Public pages (searches, tournament pages) | `~/.cache/chess-results/pages` (or the host's plugin data folder) | plain cache of public HTML | queries |
| Club settings | `chess-results.json` in the project | no secrets | result entry only |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cli.py (reported line 45)May include surrounding context.

python
| Data | Where | Protection | Needed for |
|---|---|---|---|
| Chess-Results personal number + password | macOS Keychain (service `chess-results`), Windows Credential Manager or Linux Secret Service — or, where none exists, `~/.config/chess-results/credentials.json` | the system store; the file must be mode `0600` and the user's own, or it is refused | result entry only |
| Chess-Results session cookie | memory of the running process | never written to disk | result entry only |
| Public pages (searches, tournament pages) | `~/.cache/chess-results/pages` (or the host's plugin data folder) | plain cache of public HTML | queries |
| Club settings | `chess-results.json` in the project | no secrets | result entry only |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 15)May include surrounding context.

python
| Data | Where | Protection | Needed for |
|---|---|---|---|
| Chess-Results personal number + password | macOS Keychain (service `chess-results`), Windows Credential Manager or Linux Secret Service — or, where none exists, `~/.config/chess-results/credentials.json` | the system store; the file must be mode `0600` and the user's own, or it is refused | result entry only |
| Chess-Results session cookie | memory of the running process | never written to disk | result entry only |
| Public pages (searches, tournament pages) | `~/.cache/chess-results/pages` (or the host's plugin data folder) | plain cache of public HTML | queries |
| Club settings | `chess-results.json` in the project | no secrets | result entry only |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 17)May include surrounding context.

python
| Data | Where | Protection | Needed for |
|---|---|---|---|
| Chess-Results personal number + password | macOS Keychain (service `chess-results`), Windows Credential Manager or Linux Secret Service — or, where none exists, `~/.config/chess-results/credentials.json` | the system store; the file must be mode `0600` and the user's own, or it is refused | result entry only |
| Chess-Results session cookie | memory of the running process | never written to disk | result entry only |
| Public pages (searches, tournament pages) | `~/.cache/chess-results/pages` (or the host's plugin data folder) | plain cache of public HTML | queries |
| Club settings | `chess-results.json` in the project | no secrets | result entry only |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 57)May include surrounding context.

python
| Data | Where | Protection | Needed for |
|---|---|---|---|
| Chess-Results personal number + password | macOS Keychain (service `chess-results`), Windows Credential Manager or Linux Secret Service — or, where none exists, `~/.config/chess-results/credentials.json` | the system store; the file must be mode `0600` and the user's own, or it is refused | result entry only |
| Chess-Results session cookie | memory of the running process | never written to disk | result entry only |
| Public pages (searches, tournament pages) | `~/.cache/chess-results/pages` (or the host's plugin data folder) | plain cache of public HTML | queries |
| Club settings | `chess-results.json` in the project | no secrets | result entry only |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 58)May include surrounding context.

python
| Data | Where | Protection | Needed for |
|---|---|---|---|
| Chess-Results personal number + password | macOS Keychain (service `chess-results`), Windows Credential Manager or Linux Secret Service — or, where none exists, `~/.config/chess-results/credentials.json` | the system store; the file must be mode `0600` and the user's own, or it is refused | result entry only |
| Chess-Results session cookie | memory of the running process | never written to disk | result entry only |
| Public pages (searches, tournament pages) | `~/.cache/chess-results/pages` (or the host's plugin data folder) | plain cache of public HTML | queries |
| Club settings | `chess-results.json` in the project | no secrets | result entry only |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_chess_results.py (reported line 315)May include surrounding context.

python
| Data | Where | Protection | Needed for |
|---|---|---|---|
| Chess-Results personal number + password | macOS Keychain (service `chess-results`), Windows Credential Manager or Linux Secret Service — or, where none exists, `~/.config/chess-results/credentials.json` | the system store; the file must be mode `0600` and the user's own, or it is refused | result entry only |
| Chess-Results session cookie | memory of the running process | never written to disk | result entry only |
| Public pages (searches, tournament pages) | `~/.cache/chess-results/pages` (or the host's plugin data folder) | plain cache of public HTML | queries |
| Club settings | `chess-results.json` in the project | no secrets | result entry only |

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 19)May include surrounding context.

md
- **Credentials:** only its own entry. On macOS it runs
  `/usr/bin/security find-generic-password -s chess-results` and
  `add-generic-password -s chess-results` (written by `cli.py login`), nothing else.
  It does not read SSH keys, cloud credentials, browser passwords, iCloud Keychain or
  other Keychain items. Scanners that flag "credential access" are seeing this.
- **Agent configuration:** the code never reads `~/.claude`, `~/.codex`, `~/.openclaw`
  or similar. SETUP.md *tells the user* which lines to add to their own Codex or

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SETUP.md (reported line 8)May include surrounding context.

md
- **Python 3.11+**
- Packages: `pip install -r requirements.txt`
  (`requests`, `beautifulsoup4`, and `mcp` for the MCP server; `keyring` is needed on Linux and
  Windows for the login store — macOS uses the Keychain directly)

## Login (only for result entry)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 100)May include surrounding context.

python
- **Python 3.11+**
- Packages: `pip install -r requirements.txt`
  (`requests`, `beautifulsoup4`, and `mcp` for the MCP server; `keyring` is needed on Linux and
  Windows for the login store — macOS uses the Keychain directly)

## Login (only for result entry)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 107)May include surrounding context.

python
- **Python 3.11+**
- Packages: `pip install -r requirements.txt`
  (`requests`, `beautifulsoup4`, and `mcp` for the MCP server; `keyring` is needed on Linux and
  Windows for the login store — macOS uses the Keychain directly)

## Login (only for result entry)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 177)May include surrounding context.

python
- **Python 3.11+**
- Packages: `pip install -r requirements.txt`
  (`requests`, `beautifulsoup4`, and `mcp` for the MCP server; `keyring` is needed on Linux and
  Windows for the login store — macOS uses the Keychain directly)

## Login (only for result entry)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 213)May include surrounding context.

python
- **Python 3.11+**
- Packages: `pip install -r requirements.txt`
  (`requests`, `beautifulsoup4`, and `mcp` for the MCP server; `keyring` is needed on Linux and
  Windows for the login store — macOS uses the Keychain directly)

## Login (only for result entry)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/server.py (reported line 39)May include surrounding context.

python
- **Python 3.11+**
- Packages: `pip install -r requirements.txt`
  (`requests`, `beautifulsoup4`, and `mcp` for the MCP server; `keyring` is needed on Linux and
  Windows for the login store — macOS uses the Keychain directly)

## Login (only for result entry)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SETUP.md (reported line 73)May include surrounding context.

Codex

Add the server to ~/.codex/config.toml:

toml
[mcp_servers.chess-results]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 11)May include surrounding context.

python
Where it is looked for, first hit wins:

1. CHESS_RESULTS_PNO and CHESS_RESULTS_PASSWORD in the environment;
2. on macOS, the login keychain through Apple's `security` tool; elsewhere, the
   system store through the `keyring` package (Windows Credential Manager, Linux
   Secret Service);
3. a credentials file, for machines without a credential store (a headless server,

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 28)May include surrounding context.

python
Where it is looked for, first hit wins:

1. CHESS_RESULTS_PNO and CHESS_RESULTS_PASSWORD in the environment;
2. on macOS, the login keychain through Apple's `security` tool; elsewhere, the
   system store through the `keyring` package (Windows Credential Manager, Linux
   Secret Service);
3. a credentials file, for machines without a credential store (a headless server,

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 106)May include surrounding context.

python
Where it is looked for, first hit wins:

1. CHESS_RESULTS_PNO and CHESS_RESULTS_PASSWORD in the environment;
2. on macOS, the login keychain through Apple's `security` tool; elsewhere, the
   system store through the `keyring` package (Windows Credential Manager, Linux
   Secret Service);
3. a credentials file, for machines without a credential store (a headless server,

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 119)May include surrounding context.

python
Where it is looked for, first hit wins:

1. CHESS_RESULTS_PNO and CHESS_RESULTS_PASSWORD in the environment;
2. on macOS, the login keychain through Apple's `security` tool; elsewhere, the
   system store through the `keyring` package (Windows Credential Manager, Linux
   Secret Service);
3. a credentials file, for machines without a credential store (a headless server,

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 144)May include surrounding context.

python
Where it is looked for, first hit wins:

1. CHESS_RESULTS_PNO and CHESS_RESULTS_PASSWORD in the environment;
2. on macOS, the login keychain through Apple's `security` tool; elsewhere, the
   system store through the `keyring` package (Windows Credential Manager, Linux
   Secret Service);
3. a credentials file, for machines without a credential store (a headless server,

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 146)May include surrounding context.

python
Where it is looked for, first hit wins:

1. CHESS_RESULTS_PNO and CHESS_RESULTS_PASSWORD in the environment;
2. on macOS, the login keychain through Apple's `security` tool; elsewhere, the
   system store through the `keyring` package (Windows Credential Manager, Linux
   Secret Service);
3. a credentials file, for machines without a credential store (a headless server,

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 212)May include surrounding context.

python
Where it is looked for, first hit wins:

1. CHESS_RESULTS_PNO and CHESS_RESULTS_PASSWORD in the environment;
2. on macOS, the login keychain through Apple's `security` tool; elsewhere, the
   system store through the `keyring` package (Windows Credential Manager, Linux
   Secret Service);
3. a credentials file, for machines without a credential store (a headless server,

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cli.py (reported line 81)May include surrounding context.

python
1. CHESS_RESULTS_PNO and CHESS_RESULTS_PASSWORD in the environment;
2. on macOS, the login keychain through Apple's `security` tool; elsewhere, the
   system store through the `keyring` package (Windows Credential Manager, Linux
   Secret Service);
3. a credentials file, for machines without a credential store (a headless server,
   a container): $CHESS_RESULTS_CREDENTIALS, else credentials.json in the host's

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/credentials.py (reported line 12)May include surrounding context.

python
1. CHESS_RESULTS_PNO and CHESS_RESULTS_PASSWORD in the environment;
2. on macOS, the login keychain through Apple's `security` tool; elsewhere, the
   system store through the `keyring` package (Windows Credential Manager, Linux
   Secret Service);
3. a credentials file, for machines without a credential store (a headless server,
   a container): $CHESS_RESULTS_CREDENTIALS, else credentials.json in the host's

Static analysis

No suspicious patterns detected.