Back to skill

Security audit

Accessible Game Development

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, documentation-only guide for building screen-reader-accessible HTML games, with minor usability and routing caveats but no unsafe behavior found.

Before installing, note that this skill is best suited to requests explicitly about screen-reader-accessible HTML/web games. Non-Chinese users may need to ask the agent to respond in their preferred language, and authors may want to narrow the trigger phrase to avoid unintended activation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The usage section gives a generic trigger, '开发无障碍游戏,按照 ... 编写', which overlaps with ordinary requests about game development and does not define when this skill should or should not activate. The README does not provide a bounded trigger list, exclusions, or negative examples to narrow invocation scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill content is entirely in Chinese and does not offer a user language choice, which can force responses into Chinese or bias behavior away from the user's preferred language. This is primarily a safety and usability issue: users may misunderstand guidance, and incorrect implementation advice could result if the model follows the skill language instead of the user's language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes the broad English phrase "accessible game," which lacks scope constraints and may activate the skill for unrelated requests about accessibility or games. Overly broad triggers can cause unintended routing, leading the agent to apply specialized instructions in contexts the user did not intend.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The description says the skill '支持国内争渡读屏', which imposes a China-specific product/locale focus in the skill behavior, but the README does not indicate that this is optional or limited to a region-specific use case. Under the policy, locale-specific constraints should be optional or clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.