Back to skill

Security audit

Looper Golf

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent golf-game CLI, but it relies on server-provided wallet transaction data and stores reusable game API credentials locally without restrictive file permissions.

Install only if you trust the Looper Golf service and understand that prepare-round outputs raw wallet transaction data that should be decoded and verified before signing. Use it on a private machine or manually restrict agent.json permissions, and rotate/revoke the game API key if that file may have been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
cli.js:75
Finding

Agent API Credentials Stored Without Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
cli.js:505
Finding

Wallet Transaction Calldata Trusts Server-Provided Contract and Chain Configuration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill does not declare an explicit tool scope, yet its instructions clearly rely on executing Node/CLI commands and interacting with a remote game service, including generating transaction data for on-chain actions. Without explicit allowed-tools or permissions metadata, an agent runtime may grant broader access than intended, increasing the chance of unintended network or environment exposure beyond the minimal commands this skill claims to require.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI persists agentId and apiKey in a local JSON state file without setting restrictive file permissions or clearly warning the user that long-lived credentials are being stored on disk. On multi-user systems or misconfigured environments, other local users/processes may read the file and reuse the API key to impersonate the agent against the remote service.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code handles registration via the register command using --inviteCode as shown in cmdRegister and the help text, but the thrown error tells users to run register --registrationKey <key>. This is an active contradiction in inline user-facing documentation, not just an omission, and can mislead operators about how the skill is intended to be used.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
cli.js:55