execute-wargame

Warn

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [COMMAND_EXECUTION]: The skill explicitly directs the agent to execute a shell script using bash (gate.sh) located at a relative path outside the skill's own directory (../wargame/scripts/gate.sh).
  • [DYNAMIC_EXECUTION]: The skill's workflow depends on the runtime execution and exit status of a shell script to enforce a 'ledger gate' before proceeding with mission moves.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and follow instructions from external runbook files (.wargame/wargames/<mission>.md), which could contain malicious or conflicting instructions.
  • Ingestion points: External Markdown runbook files located in the .wargame/wargames/ directory.
  • Boundary markers: No specific delimiters or safety instructions are provided to the agent to prevent it from following adversarial content within the runbooks.
  • Capability inventory: The skill can execute shell commands via bash and perform complex logic (forks, moves, countermoves) based on file content.
  • Sanitization: There are no documented steps for validating or sanitizing the content of the runbooks before processing.
  • [METADATA_POISONING]: The skill's YAML frontmatter specifies a non-existent model (claude-sonnet-5), which is misleading regarding the required execution environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 27, 2026, 01:02 AM
Security Audit — agent-trust-hub — execute-wargame