Back to skill

Security audit

Prototype

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only game prototyping workflow with no executable code, network use, credential handling, or hidden persistence; its main caveat is broad activation wording.

Install if you want a structured workflow for validating game mechanics or game jam ideas. Be aware that generic prototyping requests may activate it, so users may need to specify when they want a non-game prototyping workflow instead.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrase at line 8 is broad enough that ordinary user requests about prototyping ideas could activate this skill even when the user did not specifically want a game-development prototype workflow. Over-broad activation can cause unintended routing, irrelevant instructions, or interference with a more appropriate skill, though this file does not contain inherently dangerous actions.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Several trigger phrases in this range are ambiguous and insufficiently constrained, such as requests that could refer to generic prototyping rather than this specific game-development workflow. This creates a prompt-selection weakness where the skill may be invoked for unrelated tasks, reducing reliability and potentially causing context confusion across the system.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.