Back to skill

Security audit

Snake Rodeo

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated game-autoplay purpose, but it can spend live account game balance, installs mutable dependency code, and handles Telegram secrets too loosely.

Review this carefully before installing. Use staging first, set conservative balance limits, avoid storing Telegram bot tokens in the settings file, and treat Telegram logging as sharing gameplay/status data with Telegram and any chat members. Installation should ideally pin snake-rodeo-agents to a reviewed commit or release.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
lib/config.mjs:102
Finding

Credential-bearing settings are written without restrictive file permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
snake.mjs:172
Finding

Configuration command discloses the Telegram bot token in plaintext

Content
View full analysis
[value]'); console.log('Example: snake config strategy aggressive'); return; } ``` ### Technical Analysis Calling `snake config` without a key prints the complete settings object. Because the settings object includes `telegramBotToken`, a configured bot token is emitted in plaintext. Terminal output may be retained in shell transcripts, CI logs, agent execution records, support bundles, or screen-sharing sessions. This creates an unnecessary secret-disclosure channel unrelated to the command’s legitimate purpose of displaying configuration. A similar disclosure is possible when requesting the sensitive key directly through the single-value configuration path immediately following this block unless sensitive keys are centrally redacted. ### Attack Path 1. A Telegram bot token is stored in the Skill settings. 2. A user, automation process, or support operator runs `node snake.mjs config`. 3. The entire settings object, including `telegramBotToken`, is printed. 4. Output is recorded in a terminal transcript, CI log, agent conversation, or monitoring system. 5. A person or service with access to that output recovers and abuses the bot token. ### Impact Assessment Successful exploitation grants control over the affected Telegram bot within the permissions Telegram assigns to it. It may allow bot impersonation, unauthorized messaging, abuse of accessible updates, and disruption of the Skill’s logging channel. It does not directly expose the separately stored Trifle Bearer token. ]]>
Remediation
View remediation
[ key, SECRET_KEYS.has(key) && value ? '[REDACTED]' : value, ]) ); } console.log(JSON.stringify(redactSettings(settings), null, 2)); ``` For a direct secret query, return a value such as `"[CONFIGURED]"` or `null` rather than the credential. ]]>

T08 · Insecure Dependencies

Warning
Location
package.json:14
Finding

Core runtime dependency is fetched from an unpinned GitHub branch

Content
View full analysis
Remediation
View remediation
" ``` - Prefer a signed, versioned package release with provenance and integrity metadata. - Generate and commit a lockfile so installations resolve to the same dependency tree. - Review lifecycle scripts and install dependencies with scripts disabled where operationally possible. - Use automated dependency scanning and require review before updating the pinned revision. - Update `SKILL.md` so the upgrade procedure installs a specific reviewed version rather than the mutable default branch. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · lib/telegram.mjs (reported line 25)May include surrounding context.

js
achedToken = null;

/**
 * Send a message to Telegram
 * Token resolution: TELEGRAM_BOT_TOKEN env var → settings.telegramBotToken → null
 */
export async function sendTelegram(text, chatId = null) {
  const settings = loadSettings();
  chatId = chatId || settings.telegramChatId;

  if (!chatId) return false;
  if (!settings.logToTelegram) return false;

  if (!cachedToken) {
    cachedToken = process.env.TELEGRAM_BOT_TOKEN || settings.telegramBotToken || null;
  }

  if (!cachedToken) {
    return false;
  }

  try {
    const res = await fetch(`https://api.telegram.org/bot${cachedToken}/sendMessage`, {
      method: 'POST',
      headers: { 'Content-Type': 'application/json' },
      body: JSON.stringify({
        chat_id: chatId,
        text,
        parse_mode: 'HTML',
      }),
    });
    return res.ok;
  } catch {
    return false;
  }
}

export function formatStatus(state, settings) {
  const lines = [
    `🐍 Snake Daemon Status`,
    `├─ Strategy: ${settings.strateg

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill automates voting on a live server using the user's authenticated account and in-game balance, but the description does not clearly warn that running it can autonomously spend funds. In this context, omission of that warning is dangerous because users may enable a persistent daemon without understanding that it will place bids continuously and consume balance on their behalf.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Telegram logging sends game events to an external service and potentially to a group chat, but the documentation does not warn users about the privacy implications. In a daemon that may log gameplay activity, account-linked events, and operational status, this omission can lead to unintended disclosure of behavioral or account-related information to third parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code loads an authentication token and sends it in the Authorization header for backend requests, which is a safety-relevant network operation involving credentials. While the file has internal comments describing behavior, it lacks any user-facing prompt, log, or warning that authenticated requests will be made with locally sourced credentials.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The header comment says config is loaded from CLI arguments, environment variables, config file, and defaults in that precedence order. In this file, settings are only loaded from the JSON config file and defaults, with CLI options merged separately and only a single backend URL override read from the environment; there is no general environment-variable config loading path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

saveSettings writes arbitrary non-default settings, including fields such as telegramBotToken, into ~/.config/snake-rodeo/settings.json without any permission hardening, secret segregation, or warning. In a daemon that authenticates to external services and supports messaging integrations, persisting secrets in a general config file increases the chance of credential exposure through local reads, backups, logs, or accidental sharing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes an autoplay daemon for connecting to the game server, authenticating, and voting with AI strategies. This file invokes a shell command (sleep) via execSync, which is an OS-level capability not clearly justified by that stated game-playing purpose and exceeds what would normally be needed for server interaction or strategy execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest scopes the skill to playing Snake Rodeo, simulations, and custom strategies, but this code launches system tail processes and executes shell commands to inspect logs. OS utility execution is not an obvious requirement of gameplay automation and represents an additional capability outside the described purpose.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · lib/telegram.mjs (reported line 33)May include surrounding context.

js
}

  try {
    const res = await fetch(`https://api.telegram.org/bot${cachedToken}/sendMessage`, {
      method: 'POST',
      headers: { 'Content-Type': 'application/json' },
      body: JSON.stringify({

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The function sends the provided message text and chat ID to the Telegram API via an HTTP POST request, which transmits potentially sensitive runtime or user-related information off-system. While the file comments describe Telegram logging technically, there is no user-facing warning, confirmation, or disclosure in the code around this external data transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

When a user runs snake telegram <chat_id>, the CLI immediately transmits a test message to Telegram, an external third-party service, without an explicit warning that data is being sent off-host. Although the payload here is only a fixed test string, the behavior can surprise users and establishes an outbound channel to a configured chat, which is a privacy/transparency issue rather than a direct code-execution flaw.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation says to run snake auth login to set up auth, but the only documented commands in this skill use node snake.mjs ... and no auth subcommand appears in the command list. This creates an intent/documentation contradiction about how authentication is actually performed.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.potential_exfiltration

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
lib/process.mjs:95

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
lib/api.mjs:22

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
lib/telegram.mjs:25

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
lib/api.mjs:33