skills/akillness/jeo-skills/wai-play/Gen Agent Trust Hub

wai-play

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses local scripts (scripts/wai-play.sh and scripts/check_integration.py) for environment checks and static code validation. It also includes a command to serve local demo games for harness verification.- [DATA_EXFILTRATION]: The diagnostic 'doctor' command reads the .env file to verify configuration. It specifically reports only the names of configured keys and does not leak or transmit their values.- [PROMPT_INJECTION]: The skill processes data from external web pages and user-provided JavaScript, creating a surface for indirect prompt injection. 1. Ingestion points: Real-time browser data from web games and local integration files. 2. Boundary markers: Not present in the instruction set. 3. Capability inventory: Bash, Read, Write, Edit, and Glob. 4. Sanitization: The skill performs static text-based regex validation on integration files to prevent the execution of untrusted logic during checks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 03:05 AM
Security Audit — agent-trust-hub — wai-play