wargame
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local repository to generate wargame runbooks. This creates a surface where malicious instructions in the code could influence the generation of shell commands in the runbook.
- Ingestion points:
SKILL.md(Step 3: Recon each mission. Read the relevant code/config). - Boundary markers: None specified for the data ingestion phase.
- Capability inventory:
EXECUTE.md(Step 3: Execute the Action exactly as written), which involves shell command execution. - Sanitization: No sanitization or validation of the repository content is mentioned before it is used to formulate executable actions.
- [COMMAND_EXECUTION]: The companion
/execute-wargamecommand is designed to execute shell commands ('Actions') defined in the generated runbooks. This high-capability interface is the intended use case but remains a sensitive operation. - [DYNAMIC_EXECUTION]: The skill implements a 'generate-and-execute' workflow. It writes shell commands into markdown files based on mission recon and then executes those commands in a subsequent step. While the execution protocol in
EXECUTE.mdincludes human-in-the-loop gates (ledger resolution and abort conditions), the underlying pattern is dynamic script generation.
Audit Metadata