Back to skill

Security audit

Play Any Game - AI游戏伴侣助手

Security checks for vulnerabilities and agentic risk

Overview

This game companion is mostly recognizable as a screenshot-and-control helper, but it asks for unusually broad control over the agent and desktop without enough scoping or privacy safeguards.

Install only if you are comfortable giving the skill local desktop-control ability for games, including screenshots that may be sent to Aliyun-compatible AI services. Use a restricted API key, prefer environment-variable storage over config.json, keep the game window isolated, avoid full-screen desktop capture, and do not let SOUL files replace higher-priority host or safety instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:62
Finding

Host Agent System-Prompt Replacement

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/recognition.py:45
Finding

Arbitrary Python Evaluation in ROI Expression Parsing

Content
View full analysis
int: """ Parse an ROI expression. """ if isinstance(expr, int): return expr if isinstance(expr, str): expr = expr.replace('width', 'base').replace('height', 'base') try: return int(eval(expr, {'base': base_value})) except: return 0 return 0 ``` The evaluated value is loaded from game-specific JSON configuration: ```python config_path = os.path.join(ASSETS_DIR, game_name, 'assets', 'buttons.json') if os.path.exists(config_path): with open(config_path, 'r', encoding='utf-8') as f: _button_configs[game_name] = json.load(f) ``` ### Technical Analysis `eval` executes arbitrary Python expressions. Supplying `{'base': base_value}` as the globals dictionary does not create a safe sandbox: Python can insert or expose builtins unless they are explicitly removed, and object traversal techniques may provide additional execution paths. The current bundled `buttons.json` contains ordinary arithmetic expressions such as `width/4` and `height-70`; no embedded malicious payload was found. Nevertheless, any party capable of adding or modifying a game asset configuration can place executable Python in an ROI field. Replacing the strings `width` and `height` with `base` is not validation. It neither limits allowed syntax nor prevents function calls, imports, attribute access, comprehensions, or other Python constructs. ### Attack Path 1. An attacker modifies or introduces `games//assets/buttons.json`. 2. The attacker places a Python expression with side effects in an `roi` value. 3. The user invokes `find` or `findall` for the affected ...[truncated 1015 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/screenshot.py:195
Finding

Full-Desktop Screenshots Can Be Uploaded to a Cloud Provider

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/config.py:36
Finding

API Credentials Are Persisted in Plaintext Configuration

Content
View full analysis
None: global _config_cache config_path = get_config_dir() / CONFIG_FILE_NAME with open(config_path, 'w', encoding='utf-8') as f: json.dump(config, f, indent=2, ensure_ascii=False) _config_cache = config ``` The API key is inserted directly into this configuration: ```python def set_api_key(api_key: str, provider: str = "aliyun") -> None: config = load_config() if "gui_agent" not in config: config["gui_agent"] = {} config["gui_agent"]["api_key"] = api_key config["gui_agent"]["provider"] = provider save_config(config) ``` ### Technical Analysis The API key is written directly to `config.json` in the project directory. No operating-system credential store, encryption, access-control-list hardening, or explicit owner-only file permissions are used. The CLI masks the key when displaying configuration, which reduces accidental terminal disclosure, but it does not protect the file itself. Other processes running under the same account, users with directory access, backup systems, synchronization clients, or accidental project packaging can recover the complete credential. Documentation states that `config.json` should not be committed, but ignore rules do not protect against local access, archives, backups, or repository misconfiguration. ### Attack Path 1. The user runs the documented API-key configuration command. 2. `set_api_key` inserts the complete key into a Python dictionary. 3. `save_config` serializes the key into plaintext `config.json`. 4. A local process, another authorized directory user, backup service, or accidental archive reads the file. 5. The recovered key is used to make unauthorized API ...[truncated 464 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Dependencies Are Installed Without Reproducible Version or Integrity Constraints

Content
View full analysis
=306 Pillow>=10.0.0 opencv-python>=4.8.0 numpy>=1.24.0 openai>=1.0.0 ``` The installation instructions also permit installation through an alternate package mirror: ```bash pip install -r requirements.txt pip install -r requirements.txt -i https://pypi.tuna.tsinghua.edu.cn/simple ``` ### Technical Analysis Every dependency uses an open-ended lower bound. A later installation may therefore resolve to versions that did not exist when the Skill was audited. No lockfile, package hashes, or upper compatibility bounds are provided. Python package installation may execute package build logic, and imported packages execute code with the Skill process's privileges. Mutable dependency resolution therefore expands the trusted code base beyond the reviewed project. No typosquatted or known malicious package was identified in the listed dependencies. The finding concerns the absence of reproducibility and integrity controls rather than evidence that the current package names are malicious. ### Attack Path 1. The user follows the documented installation command. 2. `pip` resolves the newest versions satisfying the broad lower bounds. 3. A future compromised, malicious, or incompatible release is selected. 4. Package installation or later import executes that package's code. 5. The package receives the same local privileges as the Skill process. Exploitation depends on compromise of a dependency, package index, mirror, or resolution environment. ### Impact Assessment A compromised dependency can access screenshots, configuration files, API credentials, the network, and user-accessible filesystem resources. Packages such as `pywin32` also operate close to native Windows APIs, increasin ...[truncated 239 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (70)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims simple UI assistance, but it also documents keyboard injection and arbitrary window targeting, which materially increases control over the host system. This is risky because synthetic key presses can trigger unintended actions, shortcuts, or gameplay automation beyond what users expect from a helper that 'analyzes screenshots.'

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill claims simple UI assistance, but it also documents keyboard injection and arbitrary window targeting, which materially increases control over the host system. This is risky because synthetic key presses can trigger unintended actions, shortcuts, or gameplay automation beyond what users expect from a helper that 'analyzes screenshots.'

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims simple UI assistance, but it also documents keyboard injection and arbitrary window targeting, which materially increases control over the host system. This is risky because synthetic key presses can trigger unintended actions, shortcuts, or gameplay automation beyond what users expect from a helper that 'analyzes screenshots.'

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description discusses screenshot analysis but does not clearly warn that screenshots may be transmitted to an external AI service. Screenshots can contain sensitive information from the desktop or game overlays, so failing to disclose remote transmission undermines informed consent and creates privacy and data-exposure risk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 353)May include surrounding context.

md
3. 创建 `SKILL.md` - 游戏子技能说明

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill file defines a broad general-purpose assistant with capabilities far beyond the manifest's stated purpose of helping users with games. This scope mismatch is dangerous because it can authorize unrelated actions and widen the attack surface, including file manipulation, scripting, and general task execution under a game-helper label.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

Broad network search and information retrieval are outside the stated purpose of a game-companion skill and can expose users to unnecessary data handling and prompt-scope expansion. While less immediately destructive than file operations, this still increases the chance of the agent fetching untrusted content or performing unrelated actions under misleading skill branding.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Copywriting, brainstorming, and especially code writing/debugging are unrelated to a game-helper role and materially expand the skill's capabilities beyond user expectations. This can be exploited to repurpose the skill into a general agent, increasing risk of misuse, prompt confusion, and execution of unsafe or unreviewed tasks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The '检测风险' guidance explicitly recommends evasion tactics such as random delays and variable click intervals, which are classic anti-detection measures for automation. This is especially dangerous because it shows awareness that the behavior may be detected and seeks to conceal it, pushing the skill from questionable automation into deliberate stealth-oriented bot assistance.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

When no hwnd is provided, the code falls back to system-wide keyboard injection using win32api.keybd_event, allowing keystrokes to affect whichever window currently has focus. In the context of a game-helper skill, this is more dangerous because the stated purpose does not justify unrestricted desktop-wide input, and a mistake or abuse could trigger actions outside the game, including chats, terminals, browsers, or security-sensitive dialogs.

Content

No source excerpt is available for this finding.

eval() call detected

High
Category
Dangerous Code Execution
Confidence
99% confidence
Finding

The code evaluates string expressions from button configuration data using Python's eval(), which can execute arbitrary code if an attacker can modify or supply a crafted buttons.json file. Because this parser is used only to compute ROI coordinates, granting full code-execution semantics is unnecessary and creates a direct code-injection path.

Content

Scanner excerpt · scripts/recognition.py (reported line 54)May include surrounding context.

python
if isinstance(expr, str):
        expr = expr.replace('width', 'base').replace('height', 'base')
        try:
            return int(eval(expr, {'base': base_value}))
        except:
            return 0

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

ROI expressions are loaded from game asset configuration and then executed as Python code, which adds arbitrary code-execution capability unrelated to image recognition. If game assets are user-installable, downloaded, or otherwise attacker-influenced, a malicious ROI string could run commands on the host when recognition is invoked.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file explicitly frames the skill as a limited 'game companion' and 'not a game grinding tool' at L005-L012. However, later documentation introduces a closed-loop 'AI analyzes screenshot → executes action → auto-screenshots → next action' control flow and even lists '自动化操作' as a core ability in the SOUL template, which contradicts the stated non-automation intent rather than merely elaborating implementation details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill describes screenshot capture and multimodal GUI analysis using an external service, but does not prominently warn users that game-window contents may be transmitted off-device to a third-party AI provider. Because screenshots can contain chat messages, account identifiers, friend lists, payment prompts, or other sensitive on-screen data, users may unknowingly expose personal information to an external processor.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The SOUL template is documentation intended for future game integrations, and it lists '自动化操作' under core abilities. That directly conflicts with the earlier project positioning that the skill is 'not a game grinding tool' and is only meant to provide simple assistance when needed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document consistently instructs Claude behavior and example interactions entirely in Chinese, including role guidance and output examples, but does not mention any user opt-in or language selection. This can violate language/locale policy when a skill implicitly forces one language for all users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly promotes direct UI clicking on the user's behalf but does not clearly warn that the skill can control the game window or potentially misclick in ways that affect gameplay or adjacent applications. Because this is an interactive agent skill, users may underestimate the extent of system interaction and grant consent without understanding the operational risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README states that screenshots are automatically taken after every operation, but it does not provide a clear privacy warning about repeated screen capture, what area is captured, or whether sensitive information outside the game could be exposed. Continuous screenshot collection can leak chat messages, account details, overlays, notifications, or other desktop content if capture boundaries are not strictly limited.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill documents capabilities involving environment access, reading and writing config/screenshots, and system interaction, but it does not declare any explicit tool scope or permission boundaries. In an agent ecosystem, missing scope declarations make it harder to enforce least privilege and can allow broader-than-expected access to local files, secrets, and system state.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation phrases are broad enough to match ordinary requests like 'help me see how to do this,' which can trigger a high-privilege skill in contexts unrelated to gaming. Over-broad triggering is dangerous when the skill can capture screens, enumerate windows, and inject input, because accidental activation may expose data or affect the user's system unexpectedly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document says the skill is not a full automation assistant, yet it provides direct click, key, and hold commands that can automate gameplay actions. This inconsistency can mislead users and reviewers about the level of control the skill actually has, reducing informed consent and increasing abuse potential.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill says it can perform 'simple operations' but does not clearly warn that these are real mouse and keyboard actions on the live system. That omission is risky because users may not realize the skill can move the cursor, click active windows, or send keystrokes that affect unrelated applications.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Broad network search and information retrieval are outside the stated purpose of a game-companion skill and can expose users to unnecessary data handling and prompt-scope expansion. While less immediately destructive than file operations, this still increases the chance of the agent fetching untrusted content or performing unrelated actions under misleading skill branding.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Describing file operations and web search without any warning, boundary, or confirmation language is unsafe because these actions can alter user data or expose the session to external content. In a game-help skill, the lack of safeguards is more concerning because users do not reasonably expect system-affecting operations from this context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example offering to organize desktop files immediately proceeds to modify user files without a confirmation step, preview, or rollback plan. This normalizes unsafe behavior and could lead users to grant broad trust to a skill that may change important local data unintentionally.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/recognition.py:54