Back to skill

Security audit

Acca Tracker

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently tracks betting slips by checking public sports scores on a schedule, with the main risks disclosed and purpose-aligned.

Install only if you want an agent to process betting slip text or images and run periodic score checks. Review the parsed slip before approving tracking, confirm the cron job schedule and duration, and stop tracking when you no longer want background polling. The publisher should fix the metadata/version inconsistencies and explicitly include the helper script in install metadata.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger phrases are broad enough to match common sports or betting conversations such as 'check my slip' or 'monitor my bet,' which can cause unintended invocation. Because this skill can invoke web and terminal toolsets and create recurring cron jobs, accidental activation could lead to unnecessary external requests, background persistence, and user confusion about ongoing monitoring.

Static analysis

No suspicious patterns detected.