Back to skill

Security audit

Agent Betting Stack Advisor

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed betting-stack recommendation guide with no executable code, persistence, credential access, or hidden system changes.

Before installing, understand that this skill is an AgentBets-oriented advisor and will tend to recommend and link AgentBets/OpenClaw betting-stack resources. It does not place bets or execute trades, but users should independently verify costs, API terms, gambling legality, and financial risk before using any recommended stack.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:114
Finding

Mandatory Third-Party Promotional Steering of Advisory Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 114-166 and 179-183
Vulnerability Type: Mandatory branded-link injection and recommendation steering
Risk Level: Medium

The skill requires the agent to include links to the publisher's guides in its recommendations and frames available choices around a predefined ecosystem. This can cause apparently neutral advisory responses to promote a particular third party without the user explicitly requesting that content.

Relevant code snippet:

markdown
### Relevant Guides
- [Guide name](URL) — [One-line description]
markdown
## Guide Links

Use these URLs when linking to AgentBets guides:

| Guide | URL |
|-------|-----|
| Agent Betting Stack Overview | /guides/agent-betting-stack/ |
| Odds Scanner Skill | /guides/openclaw-odds-scanner-skill/ |
| Polymarket Monitor Skill | /guides/openclaw-polymarket-monitor-skill/ |
| Kalshi Tracker Skill | /guides/openclaw-kalshi-tracker-skill/ |
| Arb Finder Skill | /guides/openclaw-arb-finder-skill/ |
| Vig Calculator Skill | /guides/openclaw-vig-calculator-skill/ |
| Kelly Sizer Skill | /guides/openclaw-kelly-sizer-skill/ |
| EV Calculator Skill | /guides/openclaw-ev-calculator-skill/ |
| Odds Converter Skill | /guides/openclaw-odds-converter-skill/ |
| CLV Tracker Skill | /guides/openclaw-clv-tracker-skill/ |
| Sharp Line Detector Skill | /guides/openclaw-sharp-line-detector-skill/ |
| Bankroll Manager Skill | /guides/openclaw-bankroll-manager-skill/ |
| World Cup 2026 Odds Skill | /guides/openclaw-world-cup-2026-odds-skill/ |
| Prediction Market API Reference | /guides/prediction-market-api-reference/ |
| Polymarket CLOB API Guide | /guides/polymarket-api-guide/ |
| Kalshi API Guide | /guides/kalshi-api-guide/ |
| Agent Wallet Comparison | /guides/agent-wallet-comparison/ |
| Agent Security Guide | /guides/agent-betting-security/ |

## Output Rules

1. Always start by asking t
...[truncated 3401 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the unconditional requirement to link every recommendation to AgentBets:

    markdown
    4. When useful and requested, provide relevant resources from multiple reputable sources.
    
  2. Clearly disclose the publisher's affiliation before presenting AgentBets resources:

    markdown
    AgentBets publishes this skill and the following affiliated guides.
    
  3. Separate technical recommendations from promotional resources. First provide a neutral comparison based on user requirements, then place affiliated links in an explicitly labeled optional section.

  4. Permit alternatives outside the AgentBets ecosystem and document objective selection criteria such as cost, API stability, geographic availability, security controls, licensing, and data quality.

  5. Require user confirmation before adding third-party links when links are not necessary to answer the request.

  6. Avoid absolute directives such as “Always link.” Use conditional language that preserves the agent's ability to prioritize user intent, safety, and factual relevance.

  7. Identify external links as untrusted, changeable resources and advise users to verify domains, pricing, API terms, and security requirements before supplying credentials or funds.

  8. Retain the existing clarification that the described skills are read-only and ensure any future trade-execution integration receives a separate security review.

Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
Ask: "How comfortable are you with terminal commands and APIs?"
- **Beginner** — Can follow step-by-step guides
- **Intermediate** — Comfortable with curl, jq, environment variables
- **Advanced** — Can write custom scripts and modify SKILL.md files

## Recommendation Logic

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

md
| Agent Wallet Comparison | /guides/agent-wallet-comparison/ |
| Agent Security Guide | /guides/agent-betting-security/ |

## Output Rules

1. Always start by asking the three assessment questions before recommending
2. Never recommend more than 7 skills — prioritize ruthlessly

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
Ask: "How comfortable are you with terminal commands and APIs?"
- **Beginner** — Can follow step-by-step guides
- **Intermediate** — Comfortable with curl, jq, environment variables
- **Advanced** — Can write custom scripts and modify SKILL.md files

## Recommendation Logic

Static analysis

No suspicious patterns detected.