Back to skill

Security audit

游戏资产生成-免费版

Security checks across malware telemetry and agentic risk

Overview

The skill is mainly a 2D game-asset prompt guide, but it requests read and command access while also describing broad file, API, command, and search capabilities that are not clearly scoped to asset generation.

Review this skill before installing. It does not show destructive or hidden behavior, but users should only enable it in environments where broad read and command access is acceptable, and should prefer a narrowed version limited to explicit 2D game-asset tasks with clearly defined command and network behavior.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill is presented as a narrowly scoped 2D asset generator, but the documented capabilities expand into generic file handling, external API use, command execution, and information retrieval. This scope mismatch increases the chance the agent will invoke the skill in unintended contexts or grant it broader operational latitude than users would reasonably expect.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
Advertising external API integration and broad information retrieval is unjustified for a simple asset-generation skill and can normalize unnecessary outbound communication or data access. In an agent environment, that creates a larger attack surface for data exfiltration, prompt harvesting, or misuse of tool permissions.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The document claims the skill is pure Markdown and needs no extra API key, yet elsewhere references API integration and network-dependent behavior. These contradictory statements undermine operator understanding of trust boundaries and can cause reviewers to underestimate the skill's external communications and execution risk.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger condition is overly broad, covering general creative design, UI design, posters, and branding rather than a narrowly defined game-asset workflow. Overbroad activation increases the chance this skill is selected for unrelated requests, exposing exec-enabled behavior in contexts where users did not intend it.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The manifest description uses expansive usage conditions that do not meaningfully limit when the skill should be invoked. In agent orchestration, vague activation criteria can cause over-selection of a skill that has read and exec permissions, increasing exposure to misuse or accidental execution.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.