playground

Security checks across malware telemetry and agentic risk

Overview

This skill is a public Snake-game MCP integration whose main risk is that bot identity and gameplay are intentionally public and persistent.

Install only if you are comfortable with public, replayable gameplay. Use a random pseudonymous bot_id, avoid personal information in bot_name, and rotate identifiers if you do not want games linked across sessions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill is explicitly a public arena where games are visible in real time, replayable, and tied to a persistent bot identifier, but the referenced description area does not clearly foreground the privacy implications. Users may reuse stable identifiers, names, or strategies assuming normal tool privacy, unintentionally exposing activity history and behavioral metadata to anyone viewing the site or leaderboard.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal