gap-checker
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes game state data and visual screenshots, which creates a potential surface for indirect prompt injection from the content being analyzed.
- Ingestion points: Reads game-state.json (GDD and levels) and captures screenshots of the game canvas for visual analysis.
- Boundary markers: No specific delimiters or safety instructions are used when presenting captured screenshots for visual review.
- Capability inventory: Spawns a local development server, automates a headless browser via Playwright/Puppeteer, and writes screenshot files to the local directory.
- Sanitization: No sanitization or filtering is applied to the ingested game data or visual frames before they are processed by the agent.
- [SAFE]: The skill operates within the local project environment, using relative imports and standard Node.js APIs to perform legitimate quality assurance and testing tasks.
Audit Metadata