Back to skill

Security audit

RPG Text

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language text RPG skill with static game data and no evidence of harmful code, hidden access, or unsafe persistence.

Install this if you want a Chinese-language text RPG run by the agent. English-only users may find the commands and game text hard to follow unless they ask the agent to translate. The skill may track or summarize in-game progress, but I found no evidence that it accesses credentials, runs commands, downloads code, or persists anything outside normal game-state data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (17)

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The skill content is entirely in Chinese and presents gameplay prompts, commands, and descriptions without offering a language-selection path or documenting that the skill is intentionally limited to Chinese-speaking users. This can exclude users, impair comprehension of game instructions, and cause unsafe or incorrect interactions when users misunderstand commands or state. In this context it is not a code-execution or data-exfiltration issue, but it is still a genuine policy/usability security concern because it reduces informed user control over the interaction.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
This JSON file includes multiple natural-language description values in Chinese, but there is no indication in the file that the locale is optional, configurable, or intentionally limited to a Chinese-language audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This JSON file stores user-facing natural-language content almost entirely in Chinese for spell names and descriptions, while other fields remain in English. Because there is no indication of user opt-in, language selection, or a documented region-specific purpose, this creates a natural-language locale policy concern under the rule for forced language without user choice.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
This JSON file contains all user-facing text in Chinese, including status names and descriptions, with no indication that the skill is region-specific or that users can opt into this locale. Under the policy, forcing a specific language without user choice or justification is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The entire skill reference is written in Chinese, including headings and stat descriptions, with no indication that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
This JSON data file uses Chinese strings for season names, month names, weekdays, event descriptions, and rest effects throughout the configuration. Because there is no accompanying indication in the file that the locale is configurable or intentionally region-specific, it appears to enforce a single language without user opt-in.

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
This JSON file stores human-facing item descriptions entirely in Chinese, with no indication that the skill is China-specific or that users can opt into this locale. The policy for natural-language content flags forced language choices when no user choice or justification is provided.

Natural-Language Policy Violations

Low
Confidence
80% confidence
Finding
This JSON file contains all user-facing job descriptions in Chinese, and there is no indication in the file that users may choose another language or that the locale restriction is intentional. Under the language/locale policy rule, hard-coding a single language can be a policy concern when no opt-in or justification is provided.

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
This JSON file contains user-facing names and descriptions exclusively in Chinese, but there is no accompanying natural-language indication that the skill is China/Chinese-specific or that users can opt into this locale. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
This JSON file contains natural-language descriptions entirely in Chinese across multiple entries, but there is no indication that the skill is intentionally region-specific or that users can opt into this locale. Under the stated policy, forcing a specific language without user choice can be a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
This JSON file contains user-facing natural-language fields such as quest names and descriptions exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or documenting a justified locale constraint is a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
89% confidence
Finding
This JSON stores user-facing race names, descriptions, and features entirely in Chinese while language values such as "common" remain in English, indicating a fixed locale choice embedded in the skill data. Under the policy, forcing a specific language without user opt-in or documented regional justification is a natural-language policy concern.

Natural-Language Policy Violations

Low
Confidence
81% confidence
Finding
This JSON data uses Chinese natural-language names and descriptions throughout, such as shop names, owner names, and descriptions. Because SQP-3 applies to all file types and flags language-policy issues when a specific language is forced without opt-in, this constitutes a locale/language constraint embedded in the skill data.

Natural-Language Policy Violations

Low
Confidence
83% confidence
Finding
This JSON file contains user-facing names and descriptions in Chinese, beginning with values such as "无宝藏" and continuing throughout the dataset. Because the file provides localized content without any accompanying indication that Chinese is optional or that the skill is region-specific, it may violate the language/locale policy for skills that should not force a specific language by default.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
The title and all content are presented exclusively in Chinese, which constitutes a language/locale constraint in the skill content. The file does not offer an alternative language or indicate that the skill is intentionally limited to a Chinese-speaking or region-specific context.

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
This markdown file is entirely presented in Chinese, including headings, item names, and descriptions, with no indication that the language is optional or that the skill is intended only for a Chinese-speaking context. Under the stated policy, a fixed locale without opt-in or justification is a natural-language policy concern.

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
This markdown file presents all instructional/content text in Chinese and does not indicate that users may select another language or that the locale restriction is required for a region-specific purpose. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Static analysis

No suspicious patterns detected.