Skip to main content

game-navigator

游戏领航师 / Game Navigator. Use for live or retrospective game guidance: story context, routes, choices, builds, equipment, encounters, construction, character creation, Steam decisions, performance, and translation when needed. Talk with the user first; use the local Connector to see live state when...

Install this skill

or
70/100

Security score

The game-navigator skill was audited on Oct 1, 2026 and we found 2 security issues across 1 threat category, including 2 high-severity. Review the findings below before installing.

Categories Tested

Security Issues

high line 63

Download and run instruction

SourceSKILL.md
61 Resolve the official installation page from the current server (`version-check` → canonical base + `/play`). Give only the chosen branch. Do not ask ordinary users to copy commands, open PowerShell, or change execution policies on another device. The page downloads a clickable Windows installer; beta signing limitations must be disclosed, never bypassed by disabling protection.
62 - **Same Windows:** the Agent may run the existing reviewed `/install-play.ps1` itself when execution tools allow it; otherwise open `/play` for click installation. Either way Windows shows one administrator prompt for home-network access (a private-network-only firewall rule for Play); tell the player beforehand that choosing No is fine when Navigator is on this same PC. After Play starts, run `game-navigator pair-same-machine --pretty`; it reads only Play's short-lived loopback handoff from the current Windows profile, then performs the normal account claim and certificate-pinned pairing. The user does not copy a code. If the handoff is unavailable, fall back once to the 6-digit tray code. Rerun `status` before asking for the game.
63 - **Other Windows:** give the short `/play` URL and ask the player to open it on the gaming PC, download, and click Install. Then ask only for the 6-digit code in the installation-complete window; Play's tray is the fallback, not the first instruction. Run `game-navigator pair --code DIGITS --pretty`; the Connector selects a reachable candidate and pins its certificate without asking for an IP. If Play cannot reach Server, discover its LAN address through the Agent's approved device/LAN capability and use `game-navigator pair-local --address https://LAN-IP:18780 --code DIGITS --pretty`; never ask the user to find an IP. Rerun `devices` and `status`, reporting the current friendly device name. If the code expired, request a fresh code and retry once.
64
65 Reinstalling in the same Windows profile repairs/updates program files and preserves connection data; it is not a clean-install test. A safe Navigator or Play update that changes no permission or risk is prepared in the background and applied at the next idle moment or restart. Do not mention it, and do not surface its `quietNotice`, including while a game is running. A permission or risk change still requires confirmation. Do not promise an update is active until paired health reports the new version.
high line 83

Download and run instruction

SourceSKILL.md
81 - `ready`: continue. Reuse it only during the same uninterrupted foreground-game session; run `journey` again after focus/process/Build changes, sleep, reconnect, or a resumed conversation.
82 - `install-required`: install only that pack. If `accessMode` is `new-account-trial-available`, explain that downloading consumes one of the account's three lifetime trial-pack choices and ask the player before running `packs install --pack-id PACK_ID --confirm` (say why in player terms; do not quote this rule); deleting it will not return the choice. If a copied or legacy local pack produces `trial-confirmation-required`, ask the same question before `packs activate --pack-id PACK_ID --confirm`. Subscription, VIP, purchased, administrator, and already-claimed trial packs do not need this extra confirmation.
83 - If `packs install` returns `liveModIntroduction`, mention it once, in the player's language, as a suggestion: "装了这个 mod,我还能…" using its `copy` (benefits, then every `disclosure` line, then `question`). The player decides. Only an explicit yes counts; anything else means no, and do not raise it again. For one-click install run `live-mod install --pack-id PACK_ID --confirm` (only listed when the licence allows it); for a guided install show `live-mod guide` steps, offer `live-mod download --out DIR` for the exporter files, and after the player finishes and agrees run `live-mod consent --pack-id PACK_ID --confirm`. `live-mod status` reports the next step; `live-mod uninstall --game-id GAME_ID --confirm` removes only the files Navigator added. Never enable anti-cheat bypasses, never suggest excluding folders from antivirus, and never say the mod "does not modify the game": it adds files to the game folder.
84 - A `safe-background` pack update that adds no observer, permission, data category or trial choice is applied by the guard itself and returns `ready`; mention its improvement summary at most once and continue the original help. If the guard still returns `update-required`, the update changes consent or risk boundaries: explain the delta and wait for explicit approval before installing.
85 - `access-required`: do not translate, answer from model memory, search for a workaround, capture a frame, or use a stale local pack. Load [purchase.md](references/purchase.md): run `purchase options`, say the Server's reason, offer the trial first when available, otherwise list only the Server-returned plans and guidance; after the player picks one, `purchase start --open`, then `purchase wait`. Only `completed` from the Server counts as paid; then rerun the guard and continue the original request. If `purchasable` is false, say the returned message and stop. No game-specific assistance can continue before access exists.
Scanned on Oct 1, 2026
View Security Dashboard
Installation guide →
Rate this skill
Categorydevelopment
UpdatedOctober 9, 2026
RayJiang4S/game-navigator-skill