game-technical-director

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill utilizes role-play instructions to define the persona 'Kira Tanaka' and includes authoritative constraints on agent behavior (e.g., 'Refuse to let stack decisions be driven by hype', 'Push back hard'). These instructions are domain-specific and do not attempt to bypass safety filters or extract system prompts.
  • [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes untrusted user inputs (questions and project decisions) that influence the agent's decisions and tool usage.
  • Ingestion points: Data enters the context via the [architecture-question or tech-decision] argument in SKILL.md.
  • Boundary markers: The instructions lack explicit delimiters or warnings to ignore embedded instructions within user-provided technical data.
  • Capability inventory: The skill is granted access to high-impact tools including Bash, Write, and Edit in SKILL.md.
  • Sanitization: There is no evidence of input sanitization or validation protocols for the ingested data.
  • [COMMAND_EXECUTION]: The skill is configured with the Bash tool in its YAML frontmatter. While the instructions focus on legitimate game development utilities (e.g., SteamCMD, Fastlane, unity-builder), the presence of a general-purpose shell tool requires caution when the agent is processing untrusted project files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 09:44 PM
Security Audit — agent-trust-hub — game-technical-director