game-technique

Warn

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill requires administrative privileges to install necessary utilities and to perform memory scanning tasks on running processes.
  • Evidence: Use of sudo apt install scanmem and sudo scanmem in SKILL.md and references/memory-scanning.md.
  • [DATA_EXFILTRATION]: The skill provides scripts to access and modify the /proc/<pid>/mem interface, allowing direct interaction with a process's internal memory space, which can contain sensitive runtime information.
  • Evidence: Python scripts in SKILL.md and references/memory-scanning.md performing open(f'/proc/{pid}/mem', 'r+b', 0) and subsequent read/write operations.
  • [DYNAMIC_EXECUTION]: Python scripts for memory patching and network protocol analysis are constructed and executed dynamically using shell heredocs.
  • Evidence: `python3
  • <<'EOF'blocks found in multiple sections ofSKILL.md`.
  • [COMMAND_EXECUTION]: The skill utilizes a variety of system tools to analyze binaries and network traffic.
  • Evidence: Execution of checksec, readelf, ldd, and tcpdump for reconnaissance.
  • [EXTERNAL_DOWNLOADS]: The skill installs third-party software and libraries to facilitate game security analysis.
  • Evidence: Installation of scanmem via apt and blackboxprotobuf via pip3.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data such as game binaries and network traffic while possessing the capability to modify system files and process memory.
  • Ingestion points: Processes external binaries, save files, and network capture data.
  • Capability inventory: Can write to files and process memory, and execute shell commands.
  • Boundary markers: No markers are used to isolate or ignore instructions embedded in the processed data.
  • Sanitization: Data is processed directly without sanitization or validation of content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — game-technique