Back to skill

Security audit

Game Dev Assistant

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a local game-development helper, with some broad and risky build/export capabilities that users should control carefully.

Install only if you are comfortable with a skill that can guide local project reads/writes and Unity builds. Ask the agent to confirm before editing saves, changing versioned project files, signing, uploading, or opening exported CSVs from untrusted data in spreadsheet software.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/game_data_parser.py:83
Finding

CSV Formula Injection in Exported Game Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/build_unity.py (reported line 102)May include surrounding context.

python
"-logFile", "build.log"
    ]

    env = os.environ.copy()
    env["UNITY_OUTPUT_PATH"] = str(output_path)
    result = subprocess.run(cmd, env=env, capture_output=True, text=True)
    if result.returncode == 0:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises capabilities that clearly imply shell execution, file read/write, and environment access, but it does not declare any explicit tool scope or permissions boundaries. In an agent environment, this can cause the skill to be invoked with overly broad ambient authority, enabling unintended file modification, build/sign/upload actions, or execution of local commands without clear user-facing constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger description is extremely broad and covers many common game-development workflows, increasing the chance the skill will auto-match in contexts where sensitive actions are not expected. Because the skill includes risky operations like build automation, save editing, and packaging/signing, overbroad routing can lead to the wrong skill handling a task and exercising unnecessary privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description mentions modifying save files, asset packaging, version updates, signing, and uploads, but it does not provide a prominent warning that these operations can be destructive, irreversible, or security-sensitive. Users or upstream agents may treat the skill as routine project assistance and unintentionally permit actions that alter project artifacts, credentials-backed release flows, or player data.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/build_unity.py (reported line 21)May include surrounding context.

python
if Path(p).exists():
            return p
    # 尝试从 PATH 查找
    result = subprocess.run(['where', 'Unity'], capture_output=True, text=True)
    if result.returncode == 0:
        return result.stdout.strip().split('\n')[0]
    return None

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/build_unity.py (reported line 72)May include surrounding context.

python
]

    print(f"[INFO] 构建命令: {' '.join(cmd[:6])} ...")
    result = subprocess.run(cmd, capture_output=True, text=True)
    if result.returncode == 0:
        print(f"[OK] 构建成功: {output}")
        return True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/build_unity.py (reported line 104)May include surrounding context.

python
env = os.environ.copy()
    env["UNITY_OUTPUT_PATH"] = str(output_path)
    result = subprocess.run(cmd, env=env, capture_output=True, text=True)
    if result.returncode == 0:
        print(f"[OK] 构建成功: {output_path}")
        return True

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language strings that force a specific language for the interface, beginning with the module docstring. Under the policy, language constraints should not be imposed without user opt-in or clear justification that the tool is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script presents operational messages and CLI help text only in Chinese, and this pattern continues throughout the file. Because no language selection mechanism or locale justification is provided, this is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code file contains natural-language descriptions and user-facing messages in Chinese, beginning with the module docstring. Because the skill does not offer a language/locale choice or justify being region-specific, it violates the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The argparse description, subcommand help, and argument help strings are all presented only in Chinese. Users are not given any opt-in or alternative locale, so the skill enforces a specific language in its interactive interface.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.