skills/a-canary/arc-skills/wargame/Gen Agent Trust Hub

wargame

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local repository to generate wargame runbooks. This creates a surface where malicious instructions in the code could influence the generation of shell commands in the runbook.
  • Ingestion points: SKILL.md (Step 3: Recon each mission. Read the relevant code/config).
  • Boundary markers: None specified for the data ingestion phase.
  • Capability inventory: EXECUTE.md (Step 3: Execute the Action exactly as written), which involves shell command execution.
  • Sanitization: No sanitization or validation of the repository content is mentioned before it is used to formulate executable actions.
  • [COMMAND_EXECUTION]: The companion /execute-wargame command is designed to execute shell commands ('Actions') defined in the generated runbooks. This high-capability interface is the intended use case but remains a sensitive operation.
  • [DYNAMIC_EXECUTION]: The skill implements a 'generate-and-execute' workflow. It writes shell commands into markdown files based on mission recon and then executes those commands in a subsequent step. While the execution protocol in EXECUTE.md includes human-in-the-loop gates (ledger resolution and abort conditions), the underlying pattern is dynamic script generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:52 PM
Security Audit — agent-trust-hub — wargame