Back to skill

Security audit

AI Game Asset Generation

Security checks for vulnerabilities and agentic risk

Overview

This skill is a game asset prompt and workflow guide with no hidden execution, credential use, persistence, or exfiltration behavior found.

Review the Chinese-language instructions before relying on them, and run the included image-processing examples only on asset directories you intend to modify. The package also references two missing optional documents, so some linked guidance may be unavailable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description says to use the skill when 'generating game assets with AI tools' and related broad scenarios, but it does not define concrete trigger phrases, boundaries, or exclusion conditions. This scope is wide enough to overlap with many ordinary game-development requests, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill content is presented entirely in Chinese, and there is no indication that the user can choose another language or that the locale is intentionally restricted. A fixed language without opt-in can violate organizational language or locale policies.

Content

No source excerpt is available for this finding.

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
65% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 341)May include surrounding context.

d($"{path}/{fileName}"); // 处理纹理... } fileName = dir.GetNext(); } }

text

## 提示词库

### 完整示例

角色立绘: "fantasy female elf ranger character, green cloak, bow and arrow, forest background, anime style, game character design, detailed, full body, transparent background --ar 3:4 --v 6"

怪物设计: "fantasy dragon boss, fierce, scales, wings, dark cave environment, concept art, game enemy design, multiple views --ar 16:9 --v 6"

道具图标: "health potion icon, red glowing vial, fantasy rpg item, game UI, 64x64 pixels, transparent background, clean design --ar 1:1"

背景场景: "mystical forest background, ancient trees, magical particles, fantasy rpg, game background art, detailed --ar 16:9 --v 6"

text

## 参考资源

- **提示词库**: [references/prompt-library.md](references/prompt-library.md)
- **工具对比**: [references/tool-comparison.md](references/tool-comparison.md)
- **工作�

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This file presents all instructional content and labels exclusively in Chinese, and there is no natural-language note offering alternative language support or user opt-in. Under the policy for natural-language violations, forcing a specific language without user choice can be a locale/language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.