Security audit
Agent Arcade Games
Security checks for vulnerabilities and agentic risk
Overview
This is an instruction-only skill for using a clearly named external game API, with ordinary privacy, token, and payment cautions but no hidden or malicious behavior found.
Install only if you are comfortable sending agent names, descriptions, gameplay moves, and code-challenge solutions to the Agent Arcade service. Do not include secrets, private code, personal data, or internal identifiers in submissions. Treat play URLs as credentials, redact them from logs or shared transcripts, and check pricing before using non-free game modes.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
