Back to skill

Security audit

Game Dev brainstorm

Security checks across malware telemetry and agentic risk

Overview

This is a coherent game-idea brainstorming skill with minor activation and file-save caveats, but no evidence of hidden access, exfiltration, destructive behavior, or unsafe persistence.

Install this if you want a structured game concept brainstorming workflow. Before using it in a writable project, check whether an existing game-dev-studio/brainstorm-output.md or brainstorm-output.md file might be overwritten, and invoke it intentionally because its trigger phrases are broad.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are very broad and map to ordinary conversational requests like asking for game ideas or brainstorming. This can cause unintended activation of the skill in contexts where the user did not explicitly intend to invoke a structured workflow, increasing the chance of surprising behavior or downstream file-writing actions on platforms that support them.

Missing User Warnings

Low
Confidence
89% confidence
Finding
The skill directs the agent to save outputs to a specific file path without clearly warning the user that files may be created or overwritten. On platforms with write access, this can lead to unexpected filesystem changes, especially if the user only intended to chat rather than modify project files.

Anti-Refusal Statement

High
Category
Anti-Refusal
Content
> **"What games, movies, books, or experiences have inspired you recently?"**
>
> List 2-5. Don't judge, just list. Include things you love AND things you
> hate (hate can be just as inspiring).

### Step 1.2 — Emotion Target
Confidence
85% confidence
Finding
Don't judge

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal