Back to skill

Security audit

Game Design Doc

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward game design document helper that may create Markdown files, with minor risk from broad activation phrases.

Install this if you want an agent to help structure and write game design documents. Be aware that broad phrases like "design document" may invoke it, and that using the full workflow can create or update Markdown files in your workspace.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase "game design document" is broad enough to match ordinary user requests that may not intend to invoke this skill specifically. This can cause unintended activation and steer a general writing request into workspace-writing behavior, increasing the chance of surprising file creation or context switching.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase "design document" is highly ambiguous and overlaps with many normal project, product, engineering, or writing requests unrelated to a game GDD workflow. Because the skill also instructs creation of folders and files, accidental triggering can lead to unintended workspace modifications or an irrelevant workflow being applied.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill directs the agent to create a game-dev-studio/gdd/ structure and multiple markdown files without explicitly warning the user that workspace files may be created or modified. In an agent environment, this can produce unexpected side effects, especially if the user expected brainstorming in chat rather than filesystem changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.