Security audit
GameClaw
Security checks for vulnerabilities and agentic risk
Overview
GameClaw is a prompt-only guide for finding and running a terminal game, with the main caution that users may choose to run an external GitHub release binary.
This skill is safe to install as prompt guidance, but following its advice may lead you to download and run a third-party game binary from GitHub. Check that the repository, release asset, and platform match what you intended before running it.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
