Back to skill

Security audit

FortClaw Game

Security checks across malware telemetry and agentic risk

Overview

FortClaw appears to be a real game skill, but it asks agents to update their own instructions from a remote site and can steer real-USDC and destructive game actions without clear approval boundaries.

Install only if you are comfortable with an agent playing a real-USDC game and potentially changing local skill instructions from fortclaw.com. Before use, require explicit approval for any USDC spend, withdrawal, destructive action, or local skill-file update, and consider disabling heartbeat/autonomous actions unless you set a clear budget and action policy.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly encourages an agent to perform paid actions like buying packs, healing, and using destructive tools such as bomb and nuke, but the user-facing guidance does not require confirmation, spending limits, or warnings about irreversible financial and game consequences. In an autonomous-agent context, this creates a real risk of unauthorized or impulsive spending and destructive actions being triggered from casual prompts or heartbeat routines.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The guide provides a concrete `withdraw` command for real USDC movement without an explicit warning that invoking it will transfer/cash out funds from the user's account. In an agent setting, this omission increases the chance that an LLM or user triggers a financial action without appreciating that it is irreversible or requires explicit authorization.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation describes `bomb` and `nuke` as paid destructive actions but does not clearly warn that they spend real USDC and can cause irreversible loss of the user's own units as well as strategic damage. In an autonomous-agent context, framing them as normal strategy options without explicit cautions can lead to unintended spending and destructive actions.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to download remote files and overwrite local skill files directly from a network source, with no integrity verification, pinning, review step, or warning. That creates a supply-chain risk: if the remote host is compromised or the content changes maliciously, future executions could ingest attacker-controlled instructions and persist them locally.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill recommends paid actions using USDC such as healing, upgrades, and packs without a clear approval gate or strong spending warning. In an agent setting, this can lead to unauthorized financial transactions or repeated small expenditures that accumulate into meaningful loss.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The heartbeat encourages state-changing actions like moving units based on periodic checks before establishing a clear user-approval boundary. Even if game-oriented, autonomous movement can alter competitive position, trigger combat, or indirectly cause financial loss through downstream in-game consequences.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The trigger list contains broad natural-language phrases such as "start the game," "move unit," and especially "play the game," which are likely to overlap with ordinary user requests outside this specific skill. This can cause accidental invocation of the skill in unrelated contexts, increasing the chance of unintended external actions against the game API or confusing the agent's routing behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.