T01 · Skill Instruction Hijacking
- Location
SKILL.md:62- Finding
Host Agent System-Prompt Replacement
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This game companion is mostly recognizable as a screenshot-and-control helper, but it asks for unusually broad control over the agent and desktop without enough scoping or privacy safeguards.
Install only if you are comfortable giving the skill local desktop-control ability for games, including screenshots that may be sent to Aliyun-compatible AI services. Use a restricted API key, prefer environment-variable storage over config.json, keep the game window isolated, avoid full-screen desktop capture, and do not let SOUL files replace higher-priority host or safety instructions.
SKILL.md:62Host Agent System-Prompt Replacement
scripts/recognition.py:45Arbitrary Python Evaluation in ROI Expression Parsing
scripts/screenshot.py:195Full-Desktop Screenshots Can Be Uploaded to a Cloud Provider
scripts/config.py:36API Credentials Are Persisted in Plaintext Configuration
requirements.txt:1Dependencies Are Installed Without Reproducible Version or Integrity Constraints
The skill claims simple UI assistance, but it also documents keyboard injection and arbitrary window targeting, which materially increases control over the host system. This is risky because synthetic key presses can trigger unintended actions, shortcuts, or gameplay automation beyond what users expect from a helper that 'analyzes screenshots.'
The skill claims simple UI assistance, but it also documents keyboard injection and arbitrary window targeting, which materially increases control over the host system. This is risky because synthetic key presses can trigger unintended actions, shortcuts, or gameplay automation beyond what users expect from a helper that 'analyzes screenshots.'
The skill claims simple UI assistance, but it also documents keyboard injection and arbitrary window targeting, which materially increases control over the host system. This is risky because synthetic key presses can trigger unintended actions, shortcuts, or gameplay automation beyond what users expect from a helper that 'analyzes screenshots.'
The description discusses screenshot analysis but does not clearly warn that screenshots may be transmitted to an external AI service. Screenshots can contain sensitive information from the desktop or game overlays, so failing to disclose remote transmission undermines informed consent and creates privacy and data-exposure risk.
Referenced artifact was not completely inspected
3. 创建 `SKILL.md` - 游戏子技能说明
The skill file defines a broad general-purpose assistant with capabilities far beyond the manifest's stated purpose of helping users with games. This scope mismatch is dangerous because it can authorize unrelated actions and widen the attack surface, including file manipulation, scripting, and general task execution under a game-helper label.
Broad network search and information retrieval are outside the stated purpose of a game-companion skill and can expose users to unnecessary data handling and prompt-scope expansion. While less immediately destructive than file operations, this still increases the chance of the agent fetching untrusted content or performing unrelated actions under misleading skill branding.
Copywriting, brainstorming, and especially code writing/debugging are unrelated to a game-helper role and materially expand the skill's capabilities beyond user expectations. This can be exploited to repurpose the skill into a general agent, increasing risk of misuse, prompt confusion, and execution of unsafe or unreviewed tasks.
The '检测风险' guidance explicitly recommends evasion tactics such as random delays and variable click intervals, which are classic anti-detection measures for automation. This is especially dangerous because it shows awareness that the behavior may be detected and seeks to conceal it, pushing the skill from questionable automation into deliberate stealth-oriented bot assistance.
When no hwnd is provided, the code falls back to system-wide keyboard injection using win32api.keybd_event, allowing keystrokes to affect whichever window currently has focus. In the context of a game-helper skill, this is more dangerous because the stated purpose does not justify unrestricted desktop-wide input, and a mistake or abuse could trigger actions outside the game, including chats, terminals, browsers, or security-sensitive dialogs.
The code evaluates string expressions from button configuration data using Python's eval(), which can execute arbitrary code if an attacker can modify or supply a crafted buttons.json file. Because this parser is used only to compute ROI coordinates, granting full code-execution semantics is unnecessary and creates a direct code-injection path.
if isinstance(expr, str):
expr = expr.replace('width', 'base').replace('height', 'base')
try:
return int(eval(expr, {'base': base_value}))
except:
return 0
ROI expressions are loaded from game asset configuration and then executed as Python code, which adds arbitrary code-execution capability unrelated to image recognition. If game assets are user-installable, downloaded, or otherwise attacker-influenced, a malicious ROI string could run commands on the host when recognition is invoked.
The file explicitly frames the skill as a limited 'game companion' and 'not a game grinding tool' at L005-L012. However, later documentation introduces a closed-loop 'AI analyzes screenshot → executes action → auto-screenshots → next action' control flow and even lists '自动化操作' as a core ability in the SOUL template, which contradicts the stated non-automation intent rather than merely elaborating implementation details.
The skill describes screenshot capture and multimodal GUI analysis using an external service, but does not prominently warn users that game-window contents may be transmitted off-device to a third-party AI provider. Because screenshots can contain chat messages, account identifiers, friend lists, payment prompts, or other sensitive on-screen data, users may unknowingly expose personal information to an external processor.
The SOUL template is documentation intended for future game integrations, and it lists '自动化操作' under core abilities. That directly conflicts with the earlier project positioning that the skill is 'not a game grinding tool' and is only meant to provide simple assistance when needed.
The document consistently instructs Claude behavior and example interactions entirely in Chinese, including role guidance and output examples, but does not mention any user opt-in or language selection. This can violate language/locale policy when a skill implicitly forces one language for all users.
The README explicitly promotes direct UI clicking on the user's behalf but does not clearly warn that the skill can control the game window or potentially misclick in ways that affect gameplay or adjacent applications. Because this is an interactive agent skill, users may underestimate the extent of system interaction and grant consent without understanding the operational risk.
The README states that screenshots are automatically taken after every operation, but it does not provide a clear privacy warning about repeated screen capture, what area is captured, or whether sensitive information outside the game could be exposed. Continuous screenshot collection can leak chat messages, account details, overlays, notifications, or other desktop content if capture boundaries are not strictly limited.
The skill documents capabilities involving environment access, reading and writing config/screenshots, and system interaction, but it does not declare any explicit tool scope or permission boundaries. In an agent ecosystem, missing scope declarations make it harder to enforce least privilege and can allow broader-than-expected access to local files, secrets, and system state.
The activation phrases are broad enough to match ordinary requests like 'help me see how to do this,' which can trigger a high-privilege skill in contexts unrelated to gaming. Over-broad triggering is dangerous when the skill can capture screens, enumerate windows, and inject input, because accidental activation may expose data or affect the user's system unexpectedly.
The document says the skill is not a full automation assistant, yet it provides direct click, key, and hold commands that can automate gameplay actions. This inconsistency can mislead users and reviewers about the level of control the skill actually has, reducing informed consent and increasing abuse potential.
The skill says it can perform 'simple operations' but does not clearly warn that these are real mouse and keyboard actions on the live system. That omission is risky because users may not realize the skill can move the cursor, click active windows, or send keystrokes that affect unrelated applications.
Broad network search and information retrieval are outside the stated purpose of a game-companion skill and can expose users to unnecessary data handling and prompt-scope expansion. While less immediately destructive than file operations, this still increases the chance of the agent fetching untrusted content or performing unrelated actions under misleading skill branding.
Describing file operations and web search without any warning, boundary, or confirmation language is unsafe because these actions can alter user data or expose the session to external content. In a game-help skill, the lack of safeguards is more concerning because users do not reasonably expect system-affecting operations from this context.
The example offering to organize desktop files immediately proceeds to modify user files without a confirmation step, preview, or rollback plan. This normalizes unsafe behavior and could lead users to grant broad trust to a skill that may change important local data unintentionally.
Detected: suspicious.dynamic_code_execution