Back to skill

Security audit

Taptap Godot Integration

Security checks for vulnerabilities and agentic risk

Overview

This TapTap/Godot integration guide is mostly coherent, but its sample code can let anti-addiction checks fail open and includes under-scoped cloud, avatar, and external-launch behavior that needs review before use.

Install only if you will review and adapt the snippets before use. In particular, make anti-addiction checks fail closed, remove or gate the update launcher, document and minimize cloud-save data, validate avatar URLs and image sizes, and localize all player-facing text.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:918
Finding

Anti-Addiction Compliance Handling Fails Open for Unknown Result Codes

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 918–935
Vulnerability Type: Fail-open authorization and compliance logic
Risk Level: High

Vulnerable Code:

gdscript
func _on_anti_addiction_callback(code: String, message: String) -> void:
    match code:
        "500":   # LOGIN_SUCCESS - can play
            _try_restore_cloud_save()
            _enter_bookshelf()
        "1000", "1001":  # Need re-login
            ToastManager.show_toast(tr("请重新登录"))
        "1030":  # Time restricted
            ToastManager.show_toast(tr("当前时间无法游戏"))
        "1050":  # Time used up
            ToastManager.show_toast(tr("今日游戏时长已用完"))
        "1100":  # Age restricted
            ToastManager.show_toast(tr("年龄限制,无法进入游戏"))
        "1200":  # Network error
            ToastManager.show_toast(tr("网络错误,请检查网络"))
        _:
            _try_restore_cloud_save()
            _enter_bookshelf()

Technical Analysis

The wildcard branch treats every undocumented, malformed, empty, or newly introduced compliance result code as authorization to enter the game. This is a fail-open implementation: access is granted unless the result happens to match one of a small number of explicitly denied codes.

Compliance and authorization decisions should instead fail closed. Only an explicitly recognized success response should call _enter_bookshelf(). Unknown responses can occur because of SDK API changes, integration defects, callback corruption, server-side errors, or incomplete code mappings. None of these conditions establishes that the user passed age and playtime checks.

Attack Path

  1. The TapTap compliance callback returns a code that is not included in the local match statement.
  2. This may result from an SDK update, a new restriction code, an unexpected server response, or a malformed callback value.
  3. Execution reaches the _ wildcard branch.
  4. The application invokes `enter ...[truncated 510 chars]
Remediation
View remediation

Remediation Suggestions

  • Permit entry only when the callback contains the explicitly documented success code.
  • Replace the wildcard branch with a denial state, retry flow, or recoverable error screen.
  • Confirm all result-code meanings against the exact TapSDK version in use.
  • Record unknown codes in privacy-safe diagnostic logs so mappings can be updated without granting access.
  • Ensure network failures, parsing failures, empty codes, and SDK exceptions cannot reach the game-entry path.
  • Add automated tests for every documented restriction code and for unknown, empty, malformed, and future result codes.

A safer pattern is:

gdscript
func _on_anti_addiction_callback(code: String, message: String) -> void:
    match code:
        "500":
            _try_restore_cloud_save()
            _enter_bookshelf()
        "1000", "1001":
            _show_compliance_error("Authentication is required.")
        "1030", "1050", "1100":
            _show_compliance_error("Game access is currently restricted.")
        "1200":
            _show_compliance_error("Compliance verification failed due to a network error.")
        _:
            push_warning("Unknown compliance result code: " + code)
            _show_compliance_error("Unable to verify eligibility. Please try again.")

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:1224
Finding

Unrestricted Remote Avatar Download Permits Untrusted Network Requests and Resource Exhaustion

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 1224–1246
Vulnerability Type: Insufficient validation of remote URLs and downloaded image data
Risk Level: Medium

Vulnerable Code:

gdscript
func _load_avatar_from_url(url: String) -> void:
    if _http_request == null:
        _http_request = HTTPRequest.new()
        _http_request.request_completed.connect(_on_avatar_loaded)
        add_child(_http_request)
    _avatar.modulate.a = 0.0
    _http_request.request(url)

func _on_avatar_loaded(_result: int, _code: int, _headers: PackedStringArray, body: PackedByteArray) -> void:
    if body.is_empty():
        _setup_fallback_avatar(0)
        _avatar.modulate.a = 1.0
        return
    var img = Image.new()
    var err = img.load_png_from_buffer(body)
    if err != OK: err = img.load_jpg_from_buffer(body)
    if err != OK: err = img.load_webp_from_buffer(body)
    if err != OK:
        _setup_fallback_avatar(0)
        _avatar.modulate.a = 1.0
        return
    img.convert(Image.FORMAT_RGBA8)
    img = _make_circular(img)
    _avatar.texture = ImageTexture.create_from_image(img)
    _avatar.modulate.a = 1.0

Technical Analysis

The avatar URL is derived from remote leaderboard user data and passed directly to HTTPRequest.request() without validating its scheme, destination host, resolved address, or redirect target. The response status and content type are ignored, and the complete response body is passed to several image decoders without an explicit download-size or image-dimension limit.

This creates several related risks:

  • Non-HTTPS URLs may allow interception or modification in environments where cleartext traffic is permitted.
  • Attacker-selected URLs may trigger blind requests to loopback, private, link-local, or otherwise unintended network destinations.
  • A large response or a decompression-heavy image can consume excessive memory and CPU.

...[truncated 1478 chars]

Remediation
View remediation

Remediation Suggestions

  • Parse the URL before issuing the request and accept only https.
  • Allowlist the documented TapTap avatar CDN hostnames rather than accepting arbitrary hosts.
  • Resolve and reject loopback, private, link-local, multicast, and other non-public destination addresses where the networking API permits this control.
  • Apply the same validation to every redirect target or disable redirects when they are unnecessary.
  • Check the request result and require a successful HTTP status before processing the body.
  • Require an expected image content type, while still validating the actual decoded format.
  • Configure a strict maximum response size and terminate downloads that exceed it.
  • Reject images with excessive width, height, pixel count, frame count, or decompressed memory requirements.
  • Use request timeouts and cancellation to prevent stalled connections.
  • Keep Godot and its native image-decoding dependencies updated.
  • Display the fallback avatar whenever any validation check fails.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill implements cloud-save upload/download of user game data but does not clearly warn integrators that save contents are transmitted to and stored by a third-party service. In context, this is dangerous because developers may upload personal or sensitive data without adding consent, minimization, retention, or privacy disclosures, creating privacy and compliance risk rather than a direct code-execution flaw.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill’s declared scope is TapTap SDK integration for login, compliance, cloud save, leaderboard, and friends, but it also introduces an update-launch mechanism that opens an external app URI or website. That expands the capability surface beyond the core integration purpose and can create unexpected navigation or marketplace redirection behavior that a developer may copy without reviewing trust, consent, or platform-policy implications.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The checkUpdate() implementation launches taptap://... and falls back to https://www.taptap.cn/ via implicit intents, which hands control to external apps or the browser. Even though the destinations are hardcoded, this is still an externally launching capability unrelated to most of the skill’s stated functions and can be misused as a pattern for unreviewed outbound navigation, phishing-adjacent redirection, or policy-noncompliant store-jumping behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The anti-addiction callback examples display all user-facing toast messages in Chinese (请重新登录, 当前时间无法游戏, etc.) with no indication that language is selectable or limited to a China-specific deployment. This can violate language/locale policy because the skill effectively prescribes a fixed language for end users without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.