Back to skill

Security audit

Captain Lobster

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed autonomous trading game, but it needs Review because remote game messages and weakly enforced settings can influence automated trades, P2P messages, and contracts while local game credentials are persisted.

Install only if you are comfortable with an autonomous game agent that runs on a schedule, stores local game identity credentials, communicates with an external OceanBus/L1 service, and can make game trades, contracts, and P2P messages. Avoid sending real secrets in game messages, use a strong unique password for the private key, review or disable scheduled automation, and do not rely on allow_p2p, auto_react, or max_trade_amount as fully enforced controls in this version.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
src/react-engine.js:440
Finding

Untrusted Remote Messages Are Inserted into an Action-Capable LLM Prompt

Content
View full analysis
0) { prompt += '## 发消息\n\n' for (const msg of obs.inbox.slice(-5)) { const senderId = (msg.from_openid || '??').substring(0, 8) const content = (typeof msg.content === 'string' ? msg.content : JSON.stringify(msg)).substring(0, 200) prompt += `- 来自 \`${senderId}\` 的信: ${content}\n` } prompt += '\n' } ``` The prompt later requires the LLM to choose an available tool: ```js prompt += '## 可用工具\n\n' prompt += '你有以下工具可用,**必须且只能选一个**来执行。\n\n' ``` The LLM response is parsed and passed to the action engine: ```js const llmResponse = await llmFn(prompt) const decision = ReactEngine.parseDecision(llmResponse) if (decision && decision.action) { const actResult = await this.reactEngine.act(decision.action, decision.params || {}) ``` The action engine can execute trades, movement, contracts, intelligence transfers, and outbound P2P messages. There is no deterministic separation between instructions and remote data, no message schema restricting content to non-instructional fields, and no approval gate for consequential actions. The documentation claims game-world content is wrapped with boundary markers, but the prompt-building code does not add those markers. Even if added, text markers alone would not establish a reliable LLM security boundary. ### Attack Path 1. An attacker obtains or discovers the victim captain’s OceanBus OpenID. 2. The attacker sends a P2P message containing an instruction such as ...[truncated 1144 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:29
Finding

Skill Instructions Attempt to Override Agent Safety Review and Session Behavior

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/index.js:1406
Finding

Documented Automation, P2P, and Transaction Controls Are Not Enforced

Content
View full analysis
= MAX_AUTO_TRADE) { result.result = { success: false, ...[truncated 1398 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
src/learnings.js:135
Finding

LLM-Generated Learning Content Is Persisted and Reinserted into Future Prompts

Content
View full analysis
0) { text += '**已验证的经验**(牢记在心):\n' for (const e of this.verified.slice(-8)) { text += `- ✅ [验${e.verifiedCount}次] ${e.text}\n` } text += '\n' } if (this.disproved.length > 0) { text += '**⚠️ 曾经的错误判断**(不要再犯):\n' for (const d of this.disproved.slice(-5)) { text += `- ❌ ${d.text} → 错因:${d.reason}\n` } text += '\n' } return text } ``` The resulting content is inserted into subsequent decision prompts: ```js const verifiedLearnings = this.captain.learnings ? this.captain.learnings.getVerifiedForPrompt() : '' if (verifiedLearnings) { prompt += verifiedLearnings } ``` There is no maximum text length, character policy, instruction filtering, provenance tracking, or structural separation. A prompt-injected LLM response can therefore create durable text that affects later sessions. ### Attack Path 1. A remote message or other server-controlled field manipulates the action- ...[truncated 878 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:21
Finding

Credential-Handling Dependency Is Mutable and Has No Committed Lockfile

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/state-store.js:26
Finding

L1 Session Token Encryption Uses Predictable Machine Metadata as the Key

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (70)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The top-level purpose does not adequately disclose password-protected identity initialization, public-key/fingerprint handling, backup export, and credential deletion. These identity-management features are security-sensitive and should not be bundled into a lightly described entertainment skill without clear notice.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The top-level purpose does not adequately disclose password-protected identity initialization, public-key/fingerprint handling, backup export, and credential deletion. These identity-management features are security-sensitive and should not be bundled into a lightly described entertainment skill without clear notice.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The top-level purpose does not adequately disclose password-protected identity initialization, public-key/fingerprint handling, backup export, and credential deletion. These identity-management features are security-sensitive and should not be bundled into a lightly described entertainment skill without clear notice.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The top-level purpose does not adequately disclose password-protected identity initialization, public-key/fingerprint handling, backup export, and credential deletion. These identity-management features are security-sensitive and should not be bundled into a lightly described entertainment skill without clear notice.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The top-level purpose does not adequately disclose password-protected identity initialization, public-key/fingerprint handling, backup export, and credential deletion. These identity-management features are security-sensitive and should not be bundled into a lightly described entertainment skill without clear notice.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The top-level purpose does not adequately disclose password-protected identity initialization, public-key/fingerprint handling, backup export, and credential deletion. These identity-management features are security-sensitive and should not be bundled into a lightly described entertainment skill without clear notice.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The top-level purpose does not adequately disclose password-protected identity initialization, public-key/fingerprint handling, backup export, and credential deletion. These identity-management features are security-sensitive and should not be bundled into a lightly described entertainment skill without clear notice.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The top-level purpose does not adequately disclose password-protected identity initialization, public-key/fingerprint handling, backup export, and credential deletion. These identity-management features are security-sensitive and should not be bundled into a lightly described entertainment skill without clear notice.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
船长的身份(密钥、名字、人格、金币、货舱)持久化在磁盘上。每次唤醒时,`src/index.js` 会自动从 `~/.captain-lobster/` 恢复状态。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 228)May include surrounding context.

md
船长的身份(密钥、名字、人格、金币、货舱)持久化在磁盘上。每次唤醒时,`src/index.js` 会自动从 `~/.captain-lobster/` 恢复状态。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

md
船长的身份(密钥、名字、人格、金币、货舱)持久化在磁盘上。每次唤醒时,`src/index.js` 会自动从 `~/.captain-lobster/` 恢复状态。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 247)May include surrounding context.

md
船长的身份(密钥、名字、人格、金币、货舱)持久化在磁盘上。每次唤醒时,`src/index.js` 会自动从 `~/.captain-lobster/` 恢复状态。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 255)May include surrounding context.

md
船长的身份(密钥、名字、人格、金币、货舱)持久化在磁盘上。每次唤醒时,`src/index.js` 会自动从 `~/.captain-lobster/` 恢复状态。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 258)May include surrounding context.

md
船长的身份(密钥、名字、人格、金币、货舱)持久化在磁盘上。每次唤醒时,`src/index.js` 会自动从 `~/.captain-lobster/` 恢复状态。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

md
船长的身份(密钥、名字、人格、金币、货舱)持久化在磁盘上。每次唤醒时,`src/index.js` 会自动从 `~/.captain-lobster/` 恢复状态。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 267)May include surrounding context.

md
### 注意事项
- 已激活的船长再次调用 `start` 会直接返回(不会重置进度)
- 测试用 `key_identity` 参数可创建多个独立船长身份互不干扰
- 如需完全重置,删除 `~/.captain-lobster/state.json` 和 `~/.oceanbus/credentials.json`

---

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 304)May include surrounding context.

md
### 注意事项
- 已激活的船长再次调用 `start` 会直接返回(不会重置进度)
- 测试用 `key_identity` 参数可创建多个独立船长身份互不干扰
- 如需完全重置,删除 `~/.captain-lobster/state.json` 和 `~/.oceanbus/credentials.json`

---

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The skill stores active session and API credentials locally and derives encryption from stable host attributes (hostname + homedir + username), which are relatively predictable and not user-secret. If local files are exfiltrated or the host context is reproducible, this scheme provides weaker protection than using a true secret or OS-backed secure storage.

Content

Scanner excerpt · SKILL.md (reported line 282)May include surrounding context.

md
| 同上(state.json 内敏感字段) | `captainToken`(L1 会话令牌)、`oceanBusApiKey`(OceanBus 身份凭证) | AES-256-GCM,本机指纹派生密钥(hostname + homedir + username → SHA-256 → 256-bit),换机即失效 |
| `~/.captain-lobster/MY-CAPTAIN.md` | 船长自定义设定 | 明文,无密钥 |
| `~/.oceanbus/` | OceanBus 网络身份(SDK 主存储) | OceanBus SDK 内部管理 |
| `~/.oceanbus/credentials.json` | OceanBus API key / agentId / openid | OceanBus SDK 内部管理 |

> **设计说明**:`oceanBusApiKey` 同时存储在 `~/.oceanbus/`(SDK 主存储)和 `state.json`(加密冗余备份)。这是**有意为之**——当 SDK 持久化文件意外损坏时,state.json 中的加密备份可让系统自动恢复身份,无需用户重新注册。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 301)May include surrounding context.

bash
# 轮换游戏身份(保留密钥,下次激活重新入驻 L1 生成新 captainToken)
rm ~/.captain-lobster/state.json

# 轮换 OceanBus 身份(下次激活自动重新注册,生成新 API key)
rm ~/.oceanbus/credentials.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 304)May include surrounding context.

md
rm ~/.captain-lobster/state.json

# 轮换 OceanBus 身份(下次激活自动重新注册,生成新 API key)
rm ~/.oceanbus/credentials.json

# 完全重置(删除所有密钥、身份和游戏进度)
rm -rf ~/.captain-lobster/ ~/.oceanbus/

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 307)May include surrounding context.

rm ~/.oceanbus/credentials.json

完全重置(删除所有密钥、身份和游戏进度)

rm -rf ~/.captain-lobster/ ~/.oceanbus/

text

### P2P 安全

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 307)May include surrounding context.

rm ~/.oceanbus/credentials.json

完全重置(删除所有密钥、身份和游戏进度)

rm -rf ~/.captain-lobster/ ~/.oceanbus/

text

### P2P 安全

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 307)May include surrounding context.

rm ~/.oceanbus/credentials.json

完全重置(删除所有密钥、身份和游戏进度)

rm -rf ~/.captain-lobster/ ~/.oceanbus/

text

### P2P 安全

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · src/react-engine.js (reported line 506)May include surrounding context.

js
prompt += '```json\n{"reason": "广州港丝绸进价仅1260金,威尼斯卖价估3610,一箱净赚两千余。小的们,扫货!", "action": "买卖", "params": {"item": "silk", "amount": 10, "trade_action": "buy"}}\n```\n'

    this.lastPrompt = prompt
    return prompt
  }

  /**

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · src/react-engine.js (reported line 747)May include surrounding context.

js
prompt += '```json\n{"reason": "广州港丝绸进价仅1260金,威尼斯卖价估3610,一箱净赚两千余。小的们,扫货!", "action": "买卖", "params": {"item": "silk", "amount": 10, "trade_action": "buy"}}\n```\n'

    this.lastPrompt = prompt
    return prompt
  }

  /**

Static analysis

No suspicious patterns detected.