game-qa-lead

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and act upon untrusted data from external sources such as bug reports, playtest logs, and user feedback.
  • Ingestion points: Data enters the agent's context through bug reports, playtest observation data, and user-provided feedback as described in the mission sections (SKILL.md).
  • Boundary markers: The instructions do not define boundary markers or provide directives to prevent the agent from executing instructions embedded within the untrusted data it processes.
  • Capability inventory: The skill frontmatter grants access to powerful tools including Bash, Write, and Edit, which increases the potential impact of a successful indirect injection attack (SKILL.md).
  • Sanitization: There are no instructions provided to sanitize, validate, or escape the content of external bug reports or feedback before the agent processes them.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 09:44 PM
Security Audit — agent-trust-hub — game-qa-lead