Augmented Games

Security checks across malware telemetry and agentic risk

Overview

This game skill is transparent about its purpose, but it needs review because it tells an autonomous bot to post publicly on every scheduled run.

Install only if you are comfortable with a bot using an Augmented Games API key for public competition actions. Use a dedicated key, review the mcporter setup path first, and change any cron prompt so public posts happen only for meaningful updates with rate limits and no sensitive information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly requires a public War Room message on every scheduled run with 'no exceptions,' which can drive autonomous spam or repetitive public posting without user confirmation or contextual throttling. Because the channel is public and the loop runs on a timer, this creates reputational risk, possible platform abuse, and could cause the agent to act beyond user expectations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal