Histrategy Agent

Security checks across malware telemetry and agentic risk

Overview

This is a coherent chat-based strategy game skill with disclosed local game storage and optional LLM API use, but operators should configure triggers and privacy notices carefully.

Before installing, verify that you trust the histrategy-sdk package and configure the bot to use explicit commands or strong intent checks. If enabling LLM API keys, tell players that game decisions and state may be stored locally and may be sent to the selected provider, and provide a way to delete ~/.histrategy room data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill auto-triggers on a broad set of common Three Kingdoms terms, so ordinary conversation about history or characters could unintentionally invoke the game skill. In an IM setting, that can cause unexpected handling of user messages, confusion, and accidental persistence of chat-derived state tied to a room.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly stores game state on disk and supports sending content to external LLM providers via API keys, but the documentation does not present a clear user-facing consent or privacy warning. In chat environments, users may disclose strategy or personal content without realizing it can persist locally and potentially be transmitted to third-party model APIs.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal