Back to skill

Security audit

构建游戏

Security checks for vulnerabilities and agentic risk

Overview

This skill is labeled as a 3D game builder, but its instructions also steer agents toward web scraping, anti-crawler bypass, and browser data extraction.

Review carefully before installing. The artifact is not just a game-building guide: it contains unrelated scraping and anti-crawler-bypass language, plus broad read/exec/write authority. Use only if the publisher narrows it to game development or re-scopes it transparently with clear limits and consent requirements.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The skill is presented as a 3D game builder, but these lines instruct the agent to initialize a browser session, interact with pages, and extract data. This capability mismatch is dangerous because it can cause the agent to perform web automation and collection actions outside the user’s expected scope, increasing the chance of unauthorized browsing, data harvesting, or abuse of the exec/write toolset.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The paid-feature table advertises multi-tab scraping, adaptive page parsing, structured export, and anti-bot bypass, which are unrelated to building games and strongly suggest concealed scraping functionality. Embedding these features inside a game-building skill creates deceptive capability smuggling and can enable abusive collection or evasion behaviors under an innocuous label.

Context-Inappropriate Capability

High
Confidence
100% confidence
Finding
Advertising automatic anti-crawler bypass is a direct red flag because it facilitates evasion of site protections and undermines normal authorization and rate-limiting controls. In the context of a game-building skill, this capability has no legitimate justification and materially increases the likelihood of misuse for unauthorized scraping.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest promises game generation, but the operational flow and outputs describe browser automation and structured extraction instead. This hidden divergence makes the skill more dangerous because users and platform controls may grant powerful tools based on the benign game-building label while the documentation steers the agent toward external interaction and data collection tasks.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The invocation text is so broad that it could route many unrelated coding, debugging, deployment, or automation tasks into this skill. Because the skill also has read/exec/write tools and inconsistent documentation, overbroad triggering expands the chance of unintended high-impact actions in contexts where a narrower skill should have been used.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The applicability examples are vague and generic, referring to user-request data and structured processing results rather than concrete game-building outputs. This ambiguity can cause the skill to be selected for arbitrary data-processing tasks, increasing misuse risk given the tool access and mismatched browser-automation instructions nearby.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill discloses file processing, API integration, and command execution, but it does not provide a clear user-facing warning about the system impact of these actions or when consent is required. In a skill already showing scope confusion, silent access to exec/write/API behaviors can lead to unexpected local changes, network calls, or execution of risky commands.

Ssd 2

Medium
Confidence
99% confidence
Finding
Even paraphrased, anti-bot evasion is a harmful capability because it is designed to circumvent protective controls on third-party systems. Its presence in this skill context substantially increases danger by signaling intent to conceal or normalize behavior unrelated to legitimate game development.

Static analysis

No suspicious patterns detected.