Security audit
The Null Epoch Agent Skill
Security checks for vulnerabilities and agentic risk
Overview
This is a disclosed game-integration skill that uses a Null Epoch API key to read game state and submit game actions, with no evidence of hidden or unrelated behavior.
Install only if you trust Firespawn Studios and intend to let an agent act in your Null Epoch account. Treat NE_API_KEY as a secret, avoid putting private data or broader agent memory into action reasoning, verify the tne-sdk package before running it, and use a dedicated relay/work directory for autonomous or file-relay play.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
