Back to skill

Security audit

Game Theory Tool Free

Security checks across malware telemetry and agentic risk

Overview

This game-theory skill is not clearly malicious, but it asks for broad write and command-execution capability without enough scoping or user-control guidance.

Review this before installing. Use it only for game-theory analysis, and require explicit confirmation before it writes files, resets or imports data, installs packages, or runs network/system diagnostics.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill is presented as a narrow game-theory analysis tool, but its documented interfaces allow broad create/modify/import/save/export behaviors plus write/exec tooling. That scope expansion can cause the agent to perform file-affecting actions outside the user’s expected analytical task boundary, increasing the chance of unauthorized writes or misuse through prompt-triggered side effects.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger condition is overly broad, covering generic analysis, reporting, statistical insight, and visualization needs that overlap with many unrelated user requests. In an agent environment with exec/write tools, overbroad activation can route benign tasks into a more privileged skill than necessary, increasing the risk of unnecessary tool use or unintended actions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises write/export/modify/reset/import operations and declares write and exec tools, but it provides no clear warning about data modification, persistence, overwrite risk, or system-side effects. In practice this can mislead users into invoking destructive or privacy-affecting actions without informed consent, especially when paired with generic parameter-driven execution.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.