game-studio-harness

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool across all agent roles to perform essential development tasks, including building game code, running performance benchmarks (perf-budget.md), and executing automated matchup simulations for balance verification. These operations are within the expected scope of a software development harness.
  • [EXTERNAL_DOWNLOADS]: The skill documentation and internal roles (game-designer and game-qa) reference a dependency on an external survey skill (skill://survey). This tool is used to perform market research, genre trend analysis, and competitor benchmarking. All fetched data is stored locally in structured formats like design/trend-survey/ and qa/benchmark-notes.md.
  • [PROMPT_INJECTION]: (Indirect) The skill possesses an attack surface for indirect prompt injection because it ingests untrusted data from external sources, specifically market trends via the survey skill and user-provided intake briefs. This data is used to inform design and production decisions. The skill mitigates this risk through a rigorous 'Quality Gate' system (G1–G8) that requires numeric evidence and verification by a separate QA agent before any stage is passed, reducing the likelihood of accidental obedience to instructions embedded in external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 05:10 AM
Security Audit — agent-trust-hub — game-studio-harness