Back to skill

Security audit

爽文模拟器V1.0虾舍出品

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed paid Chinese story-game launcher, but its implicit activation plus payment and downstream skill-install flow need user review before use.

Install only if you intend to use this specific paid Chinese story-game launcher. Before approving anything, verify the scenario name, price, merchant/payment tool, and any returned paid package or signed install URL; do not share wallet credentials or payment tokens in chat.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is described as only a paid launcher, but it also instructs the agent to maintain and export detailed scenario runtime state. That creates a capability mismatch: a launcher that should only handle catalog/payment can end up storing or disclosing in-scenario state, increasing the chance of leaking paid content, user choices, or hidden game logic across handoff/debug flows.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The document first says the launcher must only handle teaser, payment, and install flow, but later tells it to maintain detailed scenario state. This contradiction weakens security boundaries and can cause implementations to overreach into the paid scenario domain, exposing hidden state or allowing unauthorized progression before entitlement is confirmed.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger list is broad and includes common conversational phrases related to starting or browsing a game-like experience. That can cause the skill to activate unintentionally during ordinary chat, which is especially risky here because the skill immediately steers toward payment and external merchant flows.

Vague Triggers

Low
Confidence
82% confidence
Finding
The activation wording around phrases like '开始游戏' or similar is ambiguous and does not define clear boundaries for when the launcher should take over. In a chat environment, such ambiguity can trigger the paid launcher in unrelated contexts, causing confusing behavior or unwanted purchase prompts.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt and metadata are broad enough to trigger the skill for generic phrases about starting a game or browsing scenarios, which can cause unintended activation without clear user intent to use this paid skill. In a commerce-like skill that promotes purchase, unlock, and install flows, overbroad invocation raises the risk of steering users into transactional or manipulative content they did not explicitly request.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill metadata and prompt are entirely oriented around Chinese-language content and a specific locale/style without indicating any user language detection or opt-in. This can cause the assistant to switch language or present localized commercial content unexpectedly, degrading user control and increasing the chance of confusion or misleading interactions.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The document says to use this flow when the user wants to buy, unlock, pay for, or enter a paid scenario, which is broad enough to match generic payment-related requests that may not be intended for this specific product. In a skill that can initiate merchant payment flows and unlock paid content, over-broad activation increases the chance of accidental or contextually incorrect payment prompts, entitlement checks, or order creation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.