Back to skill

Security audit

TheSportsDB

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a coherent TheSportsDB connector helper, but its first-time setup tells an agent to install a CLI by piping a remote script directly into a shell.

Review the setup instructions before installing. If oo is already installed and connected, the skill's normal TheSportsDB read actions are narrow and coherent. If oo is not installed, avoid blindly running the one-line curl or PowerShell installer; prefer an installation method with source review, signatures, checksums, or a trusted package manager.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the operator to install software by piping a remotely fetched script directly into bash, which is a classic arbitrary code execution pattern. If the remote host, transport, or script content is compromised, the user may execute attacker-controlled code immediately with their local privileges.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger text says to use this skill for ANY TheSportsDB request and whenever a task involves TheSportsDB, which is overly broad. Such expansive routing can cause the agent to invoke this skill automatically in situations where direct answers, safer tools, or narrower skills would be more appropriate, increasing unintended tool execution and exposure to connector-side risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest and description frame this skill as limited to searching and reading TheSportsDB data, but the Safety section and action guidance explicitly contemplate [write] and [destructive] operations. This mismatch can mislead users or downstream agents into trusting the skill as read-only when future connector actions may mutate state, increasing the chance of unintended sensitive operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.