game-studio-harness
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool across all agent roles to perform essential development tasks, including building game code, running performance benchmarks (perf-budget.md), and executing automated matchup simulations for balance verification. These operations are within the expected scope of a software development harness. - [EXTERNAL_DOWNLOADS]: The skill documentation and internal roles (
game-designerandgame-qa) reference a dependency on an externalsurveyskill (skill://survey). This tool is used to perform market research, genre trend analysis, and competitor benchmarking. All fetched data is stored locally in structured formats likedesign/trend-survey/andqa/benchmark-notes.md. - [PROMPT_INJECTION]: (Indirect) The skill possesses an attack surface for indirect prompt injection because it ingests untrusted data from external sources, specifically market trends via the
surveyskill and user-provided intake briefs. This data is used to inform design and production decisions. The skill mitigates this risk through a rigorous 'Quality Gate' system (G1–G8) that requires numeric evidence and verification by a separate QA agent before any stage is passed, reducing the likelihood of accidental obedience to instructions embedded in external content.
Audit Metadata