Back to skill

Security audit

text-game-arcade-universe-v3

Security checks across malware telemetry and agentic risk

Overview

This is a text-only game arcade skill with broad game triggers, but it does not request sensitive access or perform hidden actions.

Install if you want a chat-based text game arcade. Be aware it may activate for casual Chinese phrases about playing a game, so users who need precise skill routing may prefer narrower trigger wording or a clarification step for generic requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrase at this line ('来个小游戏') is broad, natural conversational language that can easily appear in unrelated contexts, causing the skill to activate when the user did not explicitly intend to enter this game arcade. In an agent ecosystem, overly generic activation increases prompt-scope capture risk and can interfere with other skills or normal assistant behavior, even though the content here is game-related rather than directly destructive.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The high-priority trigger list includes broad conversational phrases such as '来个小游戏', '开一局 / 来一盘 / 陪我玩', and generic requests to draw boards, which can overlap with normal chat and cause the skill to activate when the user did not clearly request this specific arcade skill. In an agent-routing context, overbroad triggers are a genuine security and safety issue because they can hijack intent resolution, override more appropriate skills, and steer the conversation into unintended behaviors.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The weak trigger section contains ambiguous phrases like '做个游戏大厅' and '画一个大一点的棋盘' that do not reliably distinguish between requesting this skill versus discussing design, UI, or unrelated examples. This increases the chance of accidental routing and unintended activation, though the impact is somewhat limited because these are labeled as weaker triggers rather than mandatory ones.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases include very generic conversational requests such as '来个小游戏', '开一局', and '陪我玩', which can match ordinary chat that is not a deliberate request to invoke this skill. In an agent environment, overly broad routing can cause unintended skill activation, hijack unrelated conversations, and bypass user intent by switching the assistant into game mode unexpectedly.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.