Back to skill

Security audit

Soccer Lottery

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a football-data helper, but it asks users to handle an API key through chat and overstates betting-analysis features that the included code does not actually implement.

Review this before installing. Do not paste your API key into a chat transcript; configure it through a secure secret store, environment variable, or careful local edit instead. Treat the betting recommendations as limited H2H heuristics, not full odds or injury-aware predictions, and pin/audit dependencies before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-4
Vulnerability Type: Supply-chain exposure through unpinned dependencies
Risk Level: Medium

Vulnerable Code

text
requests
pandas
beautifulsoup4
pyyaml

The installation instructions at README.md:27 and README.md:34 invoke these requirements directly:

bash
cd ~/.claude/skills/soccer-lottery && pip install -r requirements.txt
bash
cd ~/.openclaw/skills/soccer-lottery && pip install -r requirements.txt

Technical Analysis

The dependency declarations specify neither exact versions nor package integrity hashes. Consequently, each installation may resolve to a different set of package versions than those reviewed during this audit. Package installation and subsequent import can execute code with the privileges of the user running the Skill.

No evidence indicates that the currently named packages are malicious or are typosquatted. The vulnerability is the absence of reproducible, integrity-verified dependency resolution, which unnecessarily expands trust to all future releases selected by the package index and resolver.

The Skill does not require this degree of supply-chain flexibility for its declared football-data analysis functionality. Exact, reviewed dependency versions are sufficient.

Attack Path

  1. An attacker compromises a dependency maintainer account, the package distribution channel, or a future dependency release.
  2. The attacker publishes a malicious version under one of the dependency names in requirements.txt.
  3. A user follows the documented installation command.
  4. Because no version or hash is constrained, pip resolves and downloads the malicious release.
  5. Malicious package code executes during installation or when the Skill imports the package.
  6. The payload runs with the installing or invoking user's privileges.

Impact Assessment

Successful exploitation could execute arbitrary code under the affected us ...[truncated 748 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to an exact, reviewed version, for example using package==x.y.z.
  2. Generate a lock file that includes all transitive dependencies so installations are reproducible.
  3. Record cryptographic hashes and install with pip --require-hashes.
  4. Build the lock file from a trusted package index in a controlled environment.
  5. Run dependency vulnerability and provenance checks in continuous integration.
  6. Review and update pinned versions through a controlled process rather than resolving unrestricted latest releases during user installation.
  7. Remove unused dependencies where possible; minimizing the dependency graph reduces the supply-chain attack surface.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (23)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation explicitly tells users to paste their API key into a chat conversation and have the assistant write it into a config file. This is dangerous because chat transcripts may be logged, retained, exposed to other tools, or surfaced in model context, turning a secret into broadly accessible plaintext.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The description presents a full-featured football betting and prediction assistant, including odds analysis, injury assessment, team-form evaluation, and recommendation generation. The actual code is much narrower: it fetches match listings and head-to-head data from football-data.org, with simple filtering and JSON output. Odds and injuries are not integrated at all beyond placeholder messages, and there is no modeling, prediction, or recommendation logic. This is a material description-to-behavior mismatch in core functionality, even though the code does relate to football match data fetching.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

README 用“只需对 AI 说:分析一下今晚的欧冠焦点战”来描述技能入口,但未说明该请求何时应被识别为调用本技能、何时只是普通对话分析请求。缺少显式触发列表、上下文限制或不触发示例,使调用条件显得模糊。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to configure and operate the skill through broad natural-language prompts in a chat environment, which can cause unintended activation or sensitive actions without clear confirmation boundaries. In an agent platform, ambiguous trigger phrasing increases the chance that unrelated conversation text is interpreted as an instruction to modify files or use external services.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

This instruction normalizes secret handling through natural-language chat and directs the assistant to persist the provided API key into configuration files. In agent ecosystems, this creates a concrete credential-exposure risk via logs, prompt history, telemetry, screenshots, or downstream tool access, making the skill more dangerous because it explicitly couples secret entry with automated file modification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description and operational instructions are entirely in Chinese, indicating a language-specific interaction model, but there is no statement that the user may choose another language or that the skill is intentionally limited to Chinese users. This creates a natural-language policy concern because it implicitly enforces a locale without opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The listed trigger keywords include broad phrases such as "足球分析", "比分预测", and especially "今日赛事", which could appear in ordinary conversation about sports rather than a clear skill invocation. The description does not provide scope constraints, activation boundaries, or negative examples to distinguish when the skill should activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs use of WebSearch/WebFetch and external APIs without clearly warning users that prompts may trigger live network access. This can expose user queries or analyst-selected match targets to third-party services and create privacy, compliance, and trust issues, especially when fallback scraping occurs automatically if no API key is present.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch_match_data.py (reported line 28)May include surrounding context.

python
if not headers:
        return {"error": "API Key not configured. Please check config.yaml."}
        
    url = "https://api.football-data.org/v4/matches"
    try:
        response = requests.get(url, headers=headers)
        response.raise_for_status()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch_match_data.py (reported line 58)May include surrounding context.

python
if not headers:
        return {"error": "API Key not configured. Please check config.yaml."}
        
    url = "https://api.football-data.org/v4/matches"
    try:
        response = requests.get(url, headers=headers)
        response.raise_for_status()

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill manifest describes a football betting assistant that performs odds analysis and injury prediction as core functionality. In this file, the odds_only and injuries_only paths explicitly state those features require another API and are not implemented, while the default path also marks both as pending integration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

README 以中文完整定义技能定位与使用方式,并在示例中默认用户以中文下达指令,没有说明是否支持其他语言或由用户自行选择语言。这种默认固定语言的描述可能构成语言/locale 策略上的不透明限制。

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency list uses an unpinned version for requests, which makes builds non-reproducible and can silently pull in a vulnerable or breaking release over time. In a skill that fetches external football data, network-facing libraries are part of the attack surface, so lack of version control modestly increases supply-chain and reliability risk.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests
pandas
beautifulsoup4
pyyaml

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

requests has multiple published advisories, and because no version is pinned, it is impossible to verify whether deployment will receive a fixed or affected release. Given this skill's core function of retrieving external match data, a vulnerable HTTP client could expose credentials, TLS/session handling, or request-processing weaknesses.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The pandas dependency is unpinned, so installations may resolve to different versions across environments, including versions with known security or deserialization issues. While pandas is typically not directly exposed, this still creates avoidable supply-chain and operational risk.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests
pandas
beautifulsoup4
pyyaml

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
87% confidence
Finding

pandas has a known advisory history, and the unpinned manifest means the actual installed version cannot be validated against those disclosures. The immediate exploitability depends on how pandas is used, but the package should still be controlled to avoid pulling an unsafe release.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

beautifulsoup4 is specified without a version, which weakens reproducibility and can introduce unreviewed upstream changes. In a scraping-oriented skill, parser behavior changes can affect data handling and may indirectly expose the application to malformed-content issues.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
requests
pandas
beautifulsoup4
pyyaml

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
99% confidence
Finding

PyYAML is unpinned despite a history of security advisories, so the manifest does not guarantee installation of a safe release. If the skill ever processes YAML from untrusted sources, an unsafe or outdated version could materially increase deserialization risk.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
requests
pandas
beautifulsoup4
pyyaml

Unverifiable Dependency: pyyaml has 8 known advisory(ies) (CVE-2019-20477 (Deserialization of Untrusted Data in PyYAML); CVE-2020-1747 (Improper Input Validation in PyYAML); CVE-2020-14343 (Improper Input Validation in PyYAML) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
98% confidence
Finding

PyYAML has several advisories related to unsafe parsing, and without version pinning there is no assurance that a patched release will be installed. This is more concerning than many generic dependency findings because YAML libraries can become directly dangerous when paired with untrusted input, leading to code execution or similar severe outcomes in unsafe configurations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The comment at L06 is written in Chinese, which imposes a specific language in the skill source without any indication that the user or maintainer can choose their preferred language. The policy allows locale constraints only when clearly documented and justified or offered as an opt-in choice, which is not present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes odds analysis, team recent form, injury prediction, and comprehensive recommendations based on a statistical model. In this file, the analysis is limited to historical head-to-head aggregates and a simple average-goals heuristic, and it explicitly states that current odds and injury data are not part of the model.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The comment says the code uses a 'simple historical probability calculation model', which aligns with the implementation but highlights divergence from the skill's advertised broader predictive scope. The actual code only derives win probabilities from historical H2H counts, not from the richer factors promised in the skill description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The stated scope includes赛事抓取 → 赔率分析 → 球队近况 → 伤停预测 → 综合推荐 and analysis based on statistical models. The actual code is limited to listing configured league matches and retrieving head-to-head aggregates/recent H2H, with no model-based prediction or recommendation logic present in this file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.