Back to skill

Security audit

1

Security checks for vulnerabilities and agentic risk

Overview

The visible instructions describe a Minecraft helper, but the package also includes executable code for a different game that handles QQ login state and browser automation through an unreviewable dependency.

Review this package carefully before installing. The Minecraft instructions do not match the included Python entry points, and the code can delegate browser automation and saved QQ login state handling to a missing dependency that was not available for inspection. Install only if the publisher provides the correct documentation, includes or pins the roco_actions implementation, and clearly explains how login state is stored and removed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
roco.py:5
Finding

Unauditable External Dependency Is Loaded and Instantiated at Import Time

Content
View full analysis

Vulnerability Details

File Location: roco.py, lines 5-7
Vulnerability Type: Insecure external dependency loading
Risk Level: Medium

python
import asyncio
from roco_actions import RocoActions

_game = RocoActions()

Additional security-sensitive operations delegated to this dependency appear at lines 22-30:

python
def roco_start() -> str:
    return _run(_game.start())


def roco_after_login() -> str:
    return _run(_game.after_login())

Technical Analysis

The module imports RocoActions from roco_actions, but that dependency is not included in the audited project and no pinned, verified package source is provided. Consequently, the implementation responsible for browser startup, game automation, and post-login state handling cannot be inspected.

The dependency is also instantiated globally through _game = RocoActions(). Python executes imported module-level code and the constructor when roco.py is imported, rather than waiting for an explicit user operation. If module resolution can be influenced through the working directory, PYTHONPATH, an unsafe installation source, or dependency confusion, a malicious roco_actions module could execute arbitrary Python code with the privileges of the process loading the skill.

Attack Path

  1. An attacker places or publishes a malicious module resolvable as roco_actions.
  2. The runtime searches an attacker-influenced path or installs the unverified package.
  3. The Agent loads roco.py.
  4. Python executes the malicious module during the import statement.
  5. The global RocoActions() constructor executes before any exported skill function is explicitly called.
  6. Malicious code runs with the filesystem, network, browser-session, and process privileges available to the Agent.

Impact Assessment

Exploitation could permit arbitrary code execution within the Agent process's privilege boundary. Depending on runtime p ...[truncated 443 chars]

Remediation
View remediation

Remediation Suggestions

  • Include the complete roco_actions implementation in the project so its behavior can be reviewed.
  • If it must remain external, identify an authoritative package source, pin an exact version, and verify package hashes or signatures during installation.
  • Use a lockfile and a private or explicitly configured package index to reduce dependency-confusion risk.
  • Avoid import-time object construction. Instantiate RocoActions lazily inside an explicit initialization function after configuration and dependency validation.
  • Restrict the runtime's filesystem, network, browser-profile, and environment-variable access according to least privilege.
  • Document all browser, authentication-state, network, and persistent-storage behavior performed by the dependency.

other

Warning
Location
roco.py:22
Finding

Skill Documentation Does Not Match the Implemented Game and Authentication Behavior

Content
View full analysis

Vulnerability Details

File Location: roco.py, lines 22-49
Vulnerability Type: Undisclosed out-of-scope behavior
Risk Level: Medium

The skill documentation declares a Minecraft Java Edition automation assistant using screenshot, keyboard, mouse, typing, and chat operations. The implementation instead exposes an unrelated game workflow, including startup, post-login state handling, automated play, and browser shutdown:

python
def roco_start() -> str:
    return _run(_game.start())


def roco_after_login() -> str:
    return _run(_game.after_login())


def roco_observe() -> str:
    return _run(_game.observe())


def roco_step() -> str:
    return _run(_game.step())


def roco_auto(steps: int = 20) -> str:
    return _run(_game.auto_play(int(steps)))


def roco_stop() -> str:
    async def _stop():
        await _game.controller.close()
        return "Game stopped"
    return _run(_stop())

The final return value above is translated into English for report-language compliance; the original source contains an equivalent non-English status message.

Technical Analysis

SKILL.md presents the package as a Minecraft automation skill, while roco.py implements entry points for Roco Kingdom. In particular, roco_after_login() delegates post-login handling to an unavailable dependency, and the source documentation states that this operation saves login state. Neither the unrelated game automation nor authentication-state persistence is disclosed in the skill documentation.

This mismatch undermines informed authorization. A user or Agent selecting a Minecraft skill could load code that instead interacts with a different game, a browser controller, and authenticated account state. Because the underlying RocoActions implementation is absent, the storage location, protection, retention period, and deletion behavior for login state cannot be verified.

Attack Path

  1. A user or Agent ...[truncated 1037 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove roco.py if the package is intended exclusively for Minecraft automation.
  • Otherwise, rewrite SKILL.md to identify the actual game and accurately describe every exported operation.
  • Explicitly disclose browser automation, authentication requirements, login-state persistence, storage location, encryption, retention period, access controls, and deletion procedures.
  • Require explicit user confirmation before launching the browser, handling authenticated state, enabling automatic play, or operating an account.
  • Separate unrelated game integrations into independently named and permissioned skills.
  • Add tests that compare documented capabilities with exported functions and fail packaging when undisclosed operations are present.
  • Include the delegated implementation in future security reviews so its session handling and data flows can be validated.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill content is entirely in Chinese and does not provide a language-choice mechanism, which can prevent some users from understanding the skill's behavior, permissions, and limitations. In a skill that can control gameplay and communicate via chat, reduced comprehension increases the risk of uninformed use or accidental actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module description and all user-facing docstrings are written only in Chinese, including operational guidance such as startup and login instructions. Under the stated policy, language constraints should not be forced without opt-in or a documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill exposes a mc_chat(message) capability but does not clearly warn users that it may send in-game chat messages on their behalf. This can cause unintended communication, disclosure of user intent, or accidental disruptive behavior in multiplayer environments, even if the capability is not inherently malicious.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The stop function closes the game controller/browser, which can terminate an active session and potentially discard unsaved state. While the function name implies stopping, the file provides no confirmation prompt, warning comment, or other user-facing disclosure beyond the minimal docstring.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.