Back to skill

Security audit

街机

Security checks for vulnerabilities and agentic risk

Overview

This skill is mainly a chat-based ASCII game arcade, but it asks for broad read, write, and command execution tools and includes unrelated marketing, file, API, and command-execution claims.

Review before installing. The game instructions themselves are not malicious, and no executable payload was found, but the skill should be narrowed to game-related activation and should remove exec, broad write access, unrelated file/API claims, and API-key guidance unless those capabilities are specifically justified and scoped.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The skill is presented as a text game arcade, but later claims broad capabilities including file handling, API integration, information retrieval, and command execution. This scope mismatch is dangerous because it can cause an agent or user to authorize sensitive operations that are unrelated to the declared purpose, increasing the chance of covert misuse or privilege abuse.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
Declaring exec for a chat-based ASCII game skill is unjustified by the stated use case and creates unnecessary access to system command execution. Even without explicit payloads in this file, overprovisioned execution rights expand the attack surface and can be abused through prompt injection, tool misuse, or future changes to the skill.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The documentation introduces external API usage and API key configuration despite the skill's stated purpose being a local text game arcade. This is dangerous because it normalizes secret handling and external connectivity where none should be needed, creating opportunities for data exfiltration, credential misuse, or misleading permission requests.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The stated use case for marketing, advertising, lead conversion, and growth conflicts with the rest of the file, which describes a game arcade. Such contradictory positioning is dangerous because it obscures the real operational intent of the skill and can trick routing systems or users into invoking it in unrelated contexts with broader trust than warranted.

Vague Triggers

High
Confidence
93% confidence
Finding
The metadata includes an overly broad and mismatched trigger for marketing tasks, which can cause this skill to be selected outside its stated domain. In a tool-enabled agent environment, inappropriate routing is dangerous because a loosely scoped skill with read/write/exec capabilities may receive sensitive tasks it was never meant to handle.

Static analysis

No suspicious patterns detected.