Back to skill

Security audit

Pizzaparty Automation

Security checks for vulnerabilities and agentic risk

Overview

This skill is an account-authenticated Twitch chat automation that is partially disclosed, but it over-requests secrets, has implementation/documentation mismatches, and can post public messages without enough safeguards.

Review carefully before installing. This skill can post public Twitch chat messages using your account, may expose OAuth tokens through command history or process listings, asks for more secrets than the code uses, and does not implement the advertised PizzaParty scraping/scheduling flow. Use only with a dedicated low-privilege Twitch token, validated streamer inputs, and clear understanding of account and platform-policy risk.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
index.py:34
Finding

IRC Command Injection Through Unvalidated Channel Names

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.py:105
Finding

Twitch OAuth Token Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description does not match the behavior: the skill involves automated Twitch IRC messaging, direct use of OAuth credentials, and local output writing, while some claimed PizzaParty and scheduling functionality is not implemented. This mismatch is dangerous because it can mislead reviewers and users about what the skill actually does, hiding policy-relevant automation and credential-handling behavior.

Content

No source excerpt is available for this finding.

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · index.py (reported line 72)May include surrounding context.

python
return []

    def engage_streamer(self, name, rank="Bronze", msg_count=3):
        """Send messages to a streamer"""
        self.irc.join(name)

        for i in range(msg_count):

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises network and file-writing behavior but does not declare any explicit tool scope or permissions boundaries. In an agent ecosystem, this increases the risk of unintended capability use, makes review harder, and can allow a seemingly simple skill to perform broader actions than operators expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill describes automated Twitch chat engagement aimed at maximizing points but provides no warning about platform policy violations, account sanctions, or reputational harm. In context, this is more dangerous because it targets repeated engagement activity on a real third-party service using a personal account, increasing the chance of abuse or suspension.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown explicitly requests sensitive credentials, including OAuth tokens and client secrets, and references personal account usage without privacy or account-risk warnings. This creates a social-engineering and mishandling risk: users may paste high-value secrets into an automation context without understanding exposure, storage, or misuse consequences.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest frames the skill as "Twitch engagement via PizzaParty.gg - 4 daily sessions," which suggests activity mediated by PizzaParty.gg. In the actual code, the implemented behavior is direct connection to Twitch IRC and sending chat messages to channels, while PizzaParty.gg interaction is only mentioned as a simulated placeholder elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill accepts a Twitch OAuth token on the command line and immediately uses it for authentication. Command-line secrets can be exposed through shell history, process listings, logs, or orchestration tooling, which can lead to credential leakage and account compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code connects to Twitch IRC and sends chat messages on the user's behalf, which is a network operation that transmits account-authenticated activity to an external service. The file lacks a confirmation prompt, warning print/log, or explanatory comment/docstring disclosing that real outbound chat messages will be posted.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function documentation says it would use Playwright to scrape PizzaParty and implies it returns streamer data, but the implementation simply returns an empty list and performs no scraping. This is an active mismatch between documented intent and actual behavior, not just missing detail.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The script writes engagement results to a JSON file on disk, which is a file-write operation affecting local user data. Although the output path is configurable, the code does not provide any explicit warning, confirmation, or user-facing notice that a file will be created or overwritten.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.