game-gdd-author

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses Bash, Glob, and Grep tools during its initialization phase to check for existing design directories and files. This usage is restricted to local environment discovery to support the documentation workflow.
  • [PROMPT_INJECTION]: The skill ingests untrusted project data by reading existing Game Design Documents and notes using the Read tool. While this creates a surface for indirect prompt injection, the risk is mitigated by the skill's highly structured 10-section logic and the absence of network-enabled tools.
  • [SAFE]: No high-severity patterns such as credential harvesting, remote code execution, or persistence mechanisms were identified. The skill adheres to its stated purpose as a creative and technical documentation assistant.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 09:44 PM
Security Audit — agent-trust-hub — game-gdd-author