Back to skill

Security audit

structs-streaming

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent guide for subscribing to a game event stream, with some privacy and automation risks users should manage deliberately.

Install only if you need real-time Structs/GRASS event monitoring. Use the wildcard subscription briefly, narrow to subjects you are authorized to monitor, avoid logging unrelated player or tenant data, and use separate scoped keys for any automated actions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly recommends subscribing to the NATS wildcard subject ">" to observe all traffic, which can expose unrelated tenant, player, or operational event data if the stream is not fully isolated. Because it frames this as the default discovery method without a privacy/minimization warning, it encourages unnecessary overcollection and could normalize broad passive surveillance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.