Back to skill

Security audit

RPG Game designer

Security checks across malware telemetry and agentic risk

Overview

This is a domain-specific game-design skill with no hidden execution, data access, or persistence beyond normal browser game save guidance.

Installers should treat this as a benign game-design methodology skill. Before using it, note that it may push full trilingual game text and that its referenced references/SOP.md file is not present in the artifact, so some promised step-by-step templates are missing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest description contains broad auto-invocation language such as 'whenever the user mentions' a wide set of concepts plus open-ended upgrade/augmentation cases. That can cause the skill to activate outside narrow user intent, steering the agent into this skill's methodology even when the user did not explicitly request it. In this context the content is not overtly malicious, but overbroad routing can still override user choice and produce inappropriate or biased assistance.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The skill states that the validated source project includes trilingual copy and presents that as part of the reusable design system. In practice, this pushes the agent toward producing Chinese/English/Japanese content by default, which can conflict with the user's requested language or brevity requirements. The issue is more about coercive output shaping than direct security compromise, but it can still degrade alignment with user intent.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The instruction '三语同步:文案数组一次写齐(中/英/日)' imposes mandatory Chinese, English, and Japanese authoring without offering a language choice. This can force unnecessary disclosure, verbosity, and output shaping that overrides user preference, especially if the user only wants one language or a compact response. In context it is less dangerous than code execution or data exfiltration, but it is a genuine policy/control issue because it constrains agent behavior independent of user intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.