Videogames

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a straightforward video-game lookup tool that queries public gaming services and keeps a limited local cache.

Reasonable to install for normal game information and deal lookups. Be aware that game names or Steam app IDs you query are sent to public gaming services, and recent API responses may be cached locally for about 24 hours.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill advertises and invokes a Python script that performs network access and likely reads or writes local data, yet the skill manifest declares no permissions. This creates a transparency and policy gap: a host or user may approve the skill assuming it is low-privilege while the underlying code can still reach external services and interact with the filesystem or environment.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal