game-qa-lead
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and act upon untrusted data from external sources such as bug reports, playtest logs, and user feedback.
- Ingestion points: Data enters the agent's context through bug reports, playtest observation data, and user-provided feedback as described in the mission sections (SKILL.md).
- Boundary markers: The instructions do not define boundary markers or provide directives to prevent the agent from executing instructions embedded within the untrusted data it processes.
- Capability inventory: The skill frontmatter grants access to powerful tools including Bash, Write, and Edit, which increases the potential impact of a successful indirect injection attack (SKILL.md).
- Sanitization: There are no instructions provided to sanitize, validate, or escape the content of external bug reports or feedback before the agent processes them.
Audit Metadata