Back to skill

Security audit

MTTSports

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently controls an MTT Sports poker account, but it can spend account balance and run autonomous gameplay without mandatory limits or confirmations.

Review before installing. Only use this skill if you trust the MTT Sports CLI package and are comfortable letting an agent operate a poker account. Before any autonomous mode, set explicit limits for stakes, buy-in, total loss, add-ons, insurance, all-in actions, and session duration, and confirm how to stop both the watcher and daemon.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

High
Confidence
96% confidence
Finding
This skill explicitly supports autonomous gameplay, room entry, chip buy-in/add-on, and in-game actions that can affect funds and account state, but it does not require a prominent warning, explicit user consent, or transaction/risk confirmation boundaries. In this context, the absence of safeguards is dangerous because the agent is being instructed to make rapid account-affecting decisions in a real-money or value-bearing environment, increasing the chance of financial loss or unauthorized actions.

Static analysis

No suspicious patterns detected.