Back to skill

Security audit

游戏

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a game asset helper, but it asks for broad read, write, and shell execution authority while its activation and inputs are too generic.

Review this skill before installing if you only want game art generation. Its broad tool access and activation text could let an agent use it during unrelated coding or deployment work; install only if you are comfortable granting filesystem and command execution authority in that broader context.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is presented as a game asset generation tool, but its metadata broadens activation to code generation, debugging, testing, and deployment. This scope expansion can cause the agent to invoke a higher-risk skill in unrelated software tasks, increasing the chance of unintended file, shell, or development-environment actions.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The documentation explicitly discusses command execution risk and the manifest grants the exec tool, even though the stated purpose is asset generation. Unnecessary execution capability expands the attack surface: if the skill is auto-selected for broad development tasks, user-controlled prompts could lead to shell command execution in contexts unrelated to art generation.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The skill's schema describes generic content processing rather than concrete game asset generation inputs and outputs. This ambiguity makes the skill easier to trigger for unrelated tasks and harder to apply safe validation, especially when combined with read/write/exec capabilities.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation text is broad enough to match many general coding requests, not just game art generation. In an agent ecosystem, overbroad matching can route sensitive or high-privilege development tasks to this skill unnecessarily, increasing the likelihood of misuse of its available tools.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.