implement-fog-of-war

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions are focused on game development logic and do not contain any malicious patterns such as prompt injection, persistence mechanisms, or privilege escalation.\n- [EXTERNAL_DOWNLOADS]: The skill references a public GitHub repository (MengTo/Skills) for source material and documentation. This is a well-known service and the reference is handled neutrally.\n- [COMMAND_EXECUTION]: The validation documentation suggests running local tests using node and tsx. These are standard development workflows and do not involve executing untrusted remote code.\n- [DATA_EXFILTRATION]: No patterns of sensitive data exposure or exfiltration were found. While WebFetch is an allowed tool, it is only used for legitimate documentation references.\n- [PROMPT_INJECTION]: The skill interacts with local project files and processes game geometry data, creating a surface for indirect injection. Ingestion points: references/mechanics.md and references/validation.md. Boundary markers: Absent. Capability inventory: Bash, Write, Edit, WebFetch. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 03:01 AM
Security Audit — agent-trust-hub — implement-fog-of-war