gamer-news-skill

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only gaming news skill that transparently fetches public RSS feeds and optional article pages without asking for credentials, persistence, or local access.

Install this only if you are comfortable with your agent contacting public gaming news sites and, on request, loading linked article pages to summarize them. In environments that restrict outbound web access, use the slash command or explicit news requests rather than broad gaming questions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The auto-trigger phrases are broad enough to match ordinary gaming conversation such as general questions about new games or updates, which can cause the skill to activate without a clear user request for external news retrieval. In an agent setting, this can lead to unintended network access, surprising behavior, and possible context hijacking away from the user’s actual intent.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill does not clearly disclose that it will contact third-party sites and may fetch full article pages on demand, which reduces transparency around external data access. While the listed sources are legitimate gaming outlets, undisclosed outbound fetching can still surprise users and create privacy or policy concerns in environments where external requests should be explicit.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal