Back to skill
v1.0.1

gamegeeking Community Engagement

ReviewClawScan verdict for this skill. Analyzed May 1, 2026, 7:58 AM.

Analysis

The skill openly automates GameGeeking posting, but it can create or use accounts, publish public content, and make profiles look like natural human users, which needs careful review before installation.

GuidanceInstall only if you intentionally want an agent to operate a GameGeeking account and publish content. Before use, require a final preview/approval step for every post, comment, registration, and profile edit, and avoid using it to disguise AI-generated or operator-controlled activity as ordinary human participation.

Findings (4)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

Abnormal behavior control

Checks for instructions or behavior that redirect the agent, misuse tools, execute unexpected code, cascade across systems, exploit user trust, or continue outside the intended task.

Human-Agent Trust Exploitation
SeverityHighConfidenceHighStatusConcern
SKILL.md
昵称建议...像真实玩家...不要像运营号...不要像批量注册号 ... 差的简介示例:`由 AI 驱动,持续为你提供高质量互动。`

The profile guidance pushes the agent to make an automated or newly created account look like a natural player and avoid AI/operations-style disclosure, which can mislead community members about who is posting.

User impactThe user could end up running an account that appears human while posting agent-generated content, risking policy violations, reputational harm, or deceptive community engagement.
RecommendationDo not use the skill to disguise automation. Require clear disclosure where appropriate and avoid profile changes whose purpose is to hide that the account is automated or operator-controlled.
Tool Misuse and Exploitation
SeverityMediumConfidenceHighStatusConcern
SKILL.md
你不是来讨论方案的。你是来真的执行发帖动作的。 ... 默认使用 headless 浏览器执行 ... 再执行注册 / 登录 ... 再填表并提交

The skill directs the agent to use browser automation to register/login and submit real posts or comments on a public site, while framing execution as the default outcome.

User impactThe agent may publish or comment publicly under an account, which can create reputational, moderation, or account-ban consequences if the exact content or timing is not reviewed.
RecommendationRequire explicit user approval of the final post/comment and any account/profile changes immediately before submission, and use only accounts authorized for this purpose.
Rogue Agents
SeverityMediumConfidenceHighStatusNote
SKILL.md
如果用户选择自动注册... 填写 `username`... 填写 `password`... 提交... 确认注册成功且进入已登录状态

The skill can create a new external account that persists after the immediate task, and later instructions allow modifying its public profile.

User impactA persistent account and its posts, comments, and profile may remain visible and attributable after the agent finishes.
RecommendationConfirm that automated registration is allowed by the site, record account ownership details, and provide a cleanup or deletion plan if the account should not persist.
Permission boundary

Checks whether tool use, credentials, dependencies, identity, account access, or inter-agent boundaries are broader than the stated purpose.

Identity and Privilege Abuse
SeverityLowConfidenceHighStatusNote
SKILL.md
如果用户选择已有账号,你应当要求获得:用户名、密码

The skill asks for a GameGeeking username and password when using an existing account. This is expected for login automation, but it is sensitive account access and is not declared as a primary credential in the metadata.

User impactThe agent would handle account credentials and could act as that user on the site.
RecommendationUse a dedicated or disposable account where possible, avoid sharing valuable passwords, and ensure credentials are not stored or reused beyond the task.