Murder Mystery Writer

Security checks across malware telemetry and agentic risk

Overview

This is a coherent writing aid for murder-mystery scripts, with a spoiler-handling caveat but no evidence of credential theft, persistence, destructive behavior, or hidden execution.

Safe to install as a creative writing skill. Treat generated visualization HTML as an author/DM review artifact: do not publish or send it to players unless private scripts, hidden goals, and solution data are split into separate role-specific files or removed from the shared page.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The template embeds the full mystery solution client-side, including the murderer identity, private scripts, and hidden goals for every character. In a script-writing skill, storing spoiler content may be functionally useful for authoring or review, but exposing it directly in a browser-delivered template means any user can inspect the page source or DATA object and trivially recover secrets, defeating role separation and game integrity.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The guide instructs authors to populate a browser-openable HTML template with `scriptPrivate` and `goals`, which represent secret player information, but it does not warn that these secrets will be embedded client-side and are trivially viewable via page source or dev tools. In a murder-mystery skill, leaking hidden role details, private scripts, or secret objectives undermines game integrity and can spoil the entire experience for all players.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal