Back to skill

Security audit

游戏

Security checks across malware telemetry and agentic risk

Overview

This game-generation skill is mostly coherent, but it requests command/file authority and describes external API use beyond a clearly scoped need.

Review before installing. The skill appears intended to generate browser games, not to steal data or damage files, but it asks for broader authority than the core task clearly needs. Use it only in a workspace where file writes and possible command execution are acceptable, and avoid providing secrets or sensitive project data unless the publisher clarifies the command and network boundaries.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill advertises command execution as a core capability even though its stated purpose is one-shot game generation. In a skill with read/write/exec tools, broad command-execution claims materially increase the risk that user-controlled prompts could be turned into shell actions, enabling arbitrary code execution, filesystem changes, or environment inspection beyond what is needed to generate browser games.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The documentation claims external API integration despite the skill being presented as a local game-generation engine that outputs self-contained HTML. Unnecessary API connectivity expands the attack surface by enabling unvetted data exfiltration, prompt-to-network abuse, or use of sensitive credentials without a clear functional need.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation guidance is overly broad and lacks clear trigger boundaries or exclusions, which can cause the agent to invoke a powerful skill in contexts where it is unnecessary or unsafe. Because the skill exposes read/write/exec capabilities, vague activation criteria increase the chance of unintended file modification, code generation, or command execution from loosely related user requests.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill advertises file writing, command execution, and external API use without clear warnings about their potential effect on the host system or user data. In combination, these capabilities can modify files, run code, and transmit information off-host, so the absence of explicit risk disclosure and operational constraints makes misuse substantially more dangerous.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.