Back to skill

Security audit

Game Design One-Page Design Doc

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently creates a game design one-pager and PDF, with only ordinary file-output and dependency-installation hygiene considerations.

Install dependencies in a virtual environment and prefer a pinned ReportLab version if reproducibility matters. Review the output paths before running the renderer because it writes the requested JSON, Markdown, and PDF files and may overwrite same-named files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:60
Finding

Unpinned and Unverified Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:60-63, SKILL.md:131-136, and scripts/render_one_page_gdd.py:8-9
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

From SKILL.md:60-63:

bash
### Dependencies

```bash
pip install reportlab
text

From `SKILL.md:131-136`:

```bash
### 5. Render markdown and PDF

```bash
# Install dependency first if needed:
pip install reportlab
text

From `scripts/render_one_page_gdd.py:8-9`:

```python
Requires: reportlab  (pip install reportlab)

Technical Analysis

The project instructs users to install reportlab without specifying an exact reviewed version, verifying package hashes, using a lock file, or defining an explicitly trusted package index. Dependency resolution therefore depends on the package repository and the latest version satisfying pip's unconstrained request at installation time.

This makes installations non-reproducible and leaves the dependency supply chain insufficiently controlled. If the upstream package, a package-distribution account, the configured package index, or the network/package-resolution environment is compromised, the installation can retrieve code different from the version previously reviewed.

Python packages may execute package build or installation logic, and imported package code executes with the privileges of the process running the renderer. The project does not itself contain evidence of a malicious dependency or dependency-confusion namespace collision; the issue is the lack of version and integrity controls around the required dependency.

Attack Path

  1. An attacker compromises the relevant upstream release channel, package publishing account, configured Python package index, or another component of dependency resolution.
  2. The attacker publishes or serves a malicious artifact under the expected reportlab package name or influences resolution toward a compromised release.
  3. A user follows the d ...[truncated 1178 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin reportlab to an exact version that has been reviewed and tested:

    text
    reportlab==<reviewed-version>
    
  2. Store the dependency in a dedicated requirements or lock file rather than relying on an inline unconstrained installation command.

  3. Record cryptographic hashes for all resolved distributions and require verification during installation:

    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Generate hashes from artifacts obtained through a trusted package source, and review dependency updates before replacing the pinned version or hashes.

  5. Configure an explicitly trusted package index where appropriate, while retaining TLS certificate verification. Avoid untrusted extra indexes or dependency-resolution sources.

  6. Install dependencies inside a dedicated, unprivileged virtual environment or isolated build container. Do not recommend running pip with administrative or root privileges.

  7. Update SKILL.md and the script documentation so they reference the verified requirements file, for example:

    bash
    python -m venv .venv
    . .venv/bin/activate
    python -m pip install --require-hashes -r requirements.txt
    
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs the agent to read reference files and write JSON, Markdown, and PDF outputs, but it declares no explicit tool scope or permissions. That creates a capability/authorization mismatch: if the runtime grants broad default filesystem access, the skill could read or write beyond the intended working set, increasing the risk of unintended file access or overwrite.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description says to use the skill when a user wants a "one-page design doc, one-pager, pitchable design summary, or compact game concept sheet," which are broad natural-language phrases without explicit boundaries or exclusions. Because this is a markdown/manifest context and no negative examples or tighter trigger constraints are provided, the activation scope is ambiguous and may cause unintended invocation for general game-design requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.