Back to skill

Security audit

游戏

Security checks across malware telemetry and agentic risk

Overview

The skill is not overtly malicious, but it asks for broad write and command-execution capability without enough scoping for a game-asset helper.

Review this skill carefully before installing. It appears to be a broad automation prompt packaged as a game-asset helper; only use it where command execution and file writes are acceptable, and avoid giving it sensitive project files or secrets unless the runtime gives you clear approval controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is marketed as a game asset generation/development helper, but the documentation expands its role into generic file processing, API integration, and system command execution. This widens the operational scope beyond user expectations and creates a capability mismatch that could enable risky actions under an innocuous game-related label.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
Advertising command execution in a skill primarily framed as game asset generation is dangerous because it permits arbitrary system-side effects unrelated to the stated purpose. In an agent setting, this can be abused to run unintended commands, alter the host environment, or access sensitive local resources if the agent trusts the skill's broad instructions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation text says to use the skill for broad coding, debugging, testing, development, and deployment tasks, which greatly exceeds the stated theme of game asset generation. Overbroad invocation criteria can cause an agent to route unrelated high-impact tasks to a skill that also has write and exec capabilities, increasing the chance of unsafe actions.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill describes file writing, external API use, and command execution without an upfront warning that these actions can modify data, contact remote services, or affect the local system. In an agent ecosystem, missing impact disclosure makes accidental misuse more likely because users may assume a harmless content-generation tool while the skill can perform privileged operations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.