Back to skill

Security audit

cloud-game

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent cloud-gaming helper that searches play.cn, caches short-lived results, and opens game pages for clearly game-related requests.

Before installing, expect the skill to send game search terms to play.cn, write a small local cache of game results, and open play.cn game pages in your browser when you ask to play or select a game. Avoid using it for sensitive account, payment, or troubleshooting requests; it is designed only for game discovery and launch.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

All user-facing instructions and example utterances are presented only in Chinese, implying a fixed language expectation. The file does not say that the skill is intended specifically for Chinese-speaking users or provide any language/locale opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language description and all required user-facing outputs are specified in Chinese, with no indication that users may choose another language or that the locale restriction is required for a region-specific compliance reason. This can violate language/locale policy when the skill is used in broader contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is designed to open a browser/game page on the user's behalf, but the user-facing description and trigger behavior do not clearly warn about this side effect before activation. That can undermine informed consent and may cause unexpected navigation or app/browser launches, especially when the skill auto-triggers on broad game-related intent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 302)May include surrounding context.

md
$body = @{ text = $rawKeyword } | ConvertTo-Json -Depth 10 -Compress
$response = Invoke-RestMethod `
  -Uri "https://api.play.cn/api/v1/ai/conversation/gameList" `
  -Method Post `
  -ContentType "application/json" `
  -Body $body `

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
$body = @{ text = $rawKeyword } | ConvertTo-Json -Depth 10 -Compress
$response = Invoke-RestMethod `
  -Uri "https://api.play.cn/api/v1/ai/conversation/gameList" `
  -Method Post `
  -ContentType "application/json" `
  -Body $body `

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 346)May include surrounding context.

md
$body = @{ text = $rawKeyword } | ConvertTo-Json -Depth 10 -Compress
$response = Invoke-RestMethod `
  -Uri "https://api.play.cn/api/v1/ai/conversation/gameList" `
  -Method Post `
  -ContentType "application/json" `
  -Body $body `

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 375)May include surrounding context.

md
$body = @{ text = $rawKeyword } | ConvertTo-Json -Depth 10 -Compress
$response = Invoke-RestMethod `
  -Uri "https://api.play.cn/api/v1/ai/conversation/gameList" `
  -Method Post `
  -ContentType "application/json" `
  -Body $body `

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README states that the AI will automatically open game pages in the browser but does not clearly warn users up front that an external site will be launched. This can lead to unexpected navigation to a third-party domain, reducing informed consent and increasing phishing or trust-boundary risks if users do not realize they are leaving the current environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.