Back to skill

Security audit

Worldcup 2026 Assistant

Security checks for vulnerabilities and agentic risk

Overview

This World Cup assistant gives concrete sports-lottery betting advice and keeps local betting/profit records without clear opt-in or privacy controls.

Install only if you intentionally want a betting-oriented World Cup lottery assistant and are comfortable with it writing a local ledger of predictions, purchases, stakes, odds, returns, and profit/loss. Users should expect to review or disable the ledger behavior, avoid relying on it for financial decisions, and verify all lottery availability and odds through official channels before acting.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The manifest frames the skill as a World Cup information assistant, but the body expands into betting optimization, implied expected-value reasoning, and Poisson-based wagering workflows. That mismatch is dangerous because it hides higher-risk financial/gambling behavior from reviewers and users, reducing informed consent and bypassing policy controls that would apply to a betting-oriented skill.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The document goes beyond neutral information and instructs the assistant to produce concrete wagering tactics, stake structures, and ready-to-use betting schemes such as score parlays and selection templates. In a skill explicitly triggered by requests like '买哪场' and '推荐买', this materially enables gambling behavior and can steer users toward financial-risk decisions rather than merely explaining legal lottery rules.

Intent-Code Divergence

Medium
Confidence
87% confidence
Finding
The file gives conflicting instructions about whether zgzcw may be used to determine single-game betting availability, while elsewhere calling it prohibited or unreliable for that purpose. Inconsistency in authoritative data rules can cause the assistant to provide incorrect betting availability guidance, which is especially risky when users are told to act on time-sensitive wagering information.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The guidance assigns conflicting source priorities across sporttery screenshots, web search, zgzcw, and app data, making the execution path ambiguous. For a skill that generates actionable lottery guidance, ambiguous source precedence increases the chance of hallucinated, stale, or non-authoritative odds and purchaseability claims reaching the user.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill persistently records betting history, stake/return outcomes, and user-level ownership metadata even though its declared purpose is a general World Cup assistant. This is dangerous because it introduces sensitive behavioral profiling and financial tracking not justified by the visible product description, creating privacy and misuse risks.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The skill instructs collection of detailed gambling transaction records such as stake, odds, returns, and profit/loss. That is sensitive financial-behavior data, and storing it without necessity, consent, or safeguards increases the risk of privacy harm, surveillance of user habits, and local data exposure.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The metadata says the skill is not applicable to gambling recommendations, yet the body contains explicit betting recommendations, purchase guidance, and wagering validation workflows. This contradiction is dangerous because it can evade policy review, mislead deployers, and expose users to regulated-risk functionality they were told was excluded.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The document claims betting information should rely on domestic official sources, but later directs use of external prediction sites and non-official odds sources during prediction workflows. This inconsistency is dangerous because it can blend authoritative and non-authoritative gambling inputs, increasing the risk of inaccurate advice and misleading users about source reliability.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The code goes beyond neutral probability calculation and adds explicit betting-oriented decision support, including expected-value computation and stake labels like '轻仓' and '正常投入'. In this skill context, the manifest explicitly says it is not applicable to gambling recommendations, so these outputs can operationalize wagering behavior despite the disclaimer, creating a policy and safety violation rather than a memory-corruption style flaw.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The content introduces detailed wagering strategy content without a prominent warning about gambling losses, addictive behavior, or suitability limits. Because the surrounding skill is designed to answer purchase-oriented prompts, omission of a clear harm warning makes the advice more likely to normalize or escalate risky gambling behavior.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This section explicitly instructs the assistant to output concrete betting schemes in a reusable template, effectively operationalizing gambling recommendations without adequate safeguards. That shifts the skill from informational assistance to direct facilitation of wagering decisions, increasing user harm and compliance risk.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger list includes many broad conversational phrases like generic requests for recommendations or sports discussion, making accidental activation likely. In the context of a skill that includes betting guidance and persistent logging, overbroad triggering is especially dangerous because users may be routed into regulated or privacy-invasive behavior without clear intent.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill mandates persistent storage of betting and profit/loss records but provides no user notice, consent, or privacy controls. In context, this is dangerous because it silently creates a sensitive behavioral ledger tied to an owner identity and financial activity, which users may not reasonably expect from a sports assistant.

Ssd 3

Medium
Confidence
95% confidence
Finding
The instructions require persistent local logging of betting activity, ownership metadata, bet amounts, returns, and follow-up notifications. This is dangerous because routine persistence of sensitive user behavior expands the blast radius of local compromise and normalizes data collection beyond the core informational purpose of the skill.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill directs the agent to sync every prediction, recommendation, and confirmed purchase into persistent files. That is risky because it creates comprehensive longitudinal profiling of gambling-related behavior and decisions, even for recommendations that may not reflect actual transactions.

Ssd 3

Medium
Confidence
93% confidence
Finding
The skill tells the agent to proactively update outcomes and notify users of profit/loss based on stored betting records. This is dangerous because it turns a one-off assistant into an ongoing monitoring system for sensitive gambling behavior, increasing privacy exposure and encouraging continued wagering engagement.

Static analysis

No suspicious patterns detected.