make-game

Fail

Audited by Socket on Mar 13, 2026

2 alerts found:

SecurityObfuscated File
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core game-building workflow is plausible, but the skill’s footprint goes far beyond scaffolding: it installs other skills, performs public deployment/monetization, reads raw local credential files, and most critically instructs the agent to embed the user's Play.fun API key into publicly served HTML. That credential-handling behavior is fundamentally inconsistent with a safe game-creation skill and drives the overall risk high.

Confidence: 92%Severity: 93%
Obfuscated FileHIGH
tweet-pipeline.md

No direct signs of malware or obfuscation in the textual specification. The principal risks are privacy, legal (likeness/copyright), and supply-chain exfiltration from sending tweet text and detected names to external services and storing API keys insecurely. The 'NEVER refuse' mandate increases the likelihood of generating disallowed or sensitive content. Recommend adding explicit content-moderation, secure secret handling, consent/rights checks before likeness generation, logging/redaction policies, and the ability to refuse generation for prohibited inputs.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 13, 2026, 08:47 AM
Package URL
pkg:socket/skills-sh/opusgamelabs%2Fgame-creator%2Fmake-game%2F@3f38caf20f9e5d396789489da080661b876529f2