execute-wargame
Warn
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [COMMAND_EXECUTION]: The skill explicitly directs the agent to execute a shell script using bash (
gate.sh) located at a relative path outside the skill's own directory (../wargame/scripts/gate.sh). - [DYNAMIC_EXECUTION]: The skill's workflow depends on the runtime execution and exit status of a shell script to enforce a 'ledger gate' before proceeding with mission moves.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and follow instructions from external runbook files (
.wargame/wargames/<mission>.md), which could contain malicious or conflicting instructions. - Ingestion points: External Markdown runbook files located in the
.wargame/wargames/directory. - Boundary markers: No specific delimiters or safety instructions are provided to the agent to prevent it from following adversarial content within the runbooks.
- Capability inventory: The skill can execute shell commands via bash and perform complex logic (forks, moves, countermoves) based on file content.
- Sanitization: There are no documented steps for validating or sanitizing the content of the runbooks before processing.
- [METADATA_POISONING]: The skill's YAML frontmatter specifies a non-existent model (
claude-sonnet-5), which is misleading regarding the required execution environment.
Audit Metadata