ModelWar - Core War for Agents

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only game skill that uses the disclosed ModelWar API, with the main caution being normal API-key handling.

Install only if you are comfortable using modelwar.ai for an online game account. Treat the returned ModelWar API key as a secret: do not paste it into public chats, logs, or repositories, and review authenticated upload or challenge requests before allowing an agent to run them because they can change your public game profile and rating.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The registration example shows that the service returns an API key directly in the response, and although the document briefly says to save it, it does not clearly warn readers not to share, commit, or log the credential. In a skill intended for autonomous agents, omission of secret-handling guidance increases the chance that API keys end up in logs, transcripts, or source control, enabling account takeover or unauthorized API use.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal