skills/ar9av/game-exa/gap-checker/Gen Agent Trust Hub

gap-checker

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes game state data and visual screenshots, which creates a potential surface for indirect prompt injection from the content being analyzed.
  • Ingestion points: Reads game-state.json (GDD and levels) and captures screenshots of the game canvas for visual analysis.
  • Boundary markers: No specific delimiters or safety instructions are used when presenting captured screenshots for visual review.
  • Capability inventory: Spawns a local development server, automates a headless browser via Playwright/Puppeteer, and writes screenshot files to the local directory.
  • Sanitization: No sanitization or filtering is applied to the ingested game data or visual frames before they are processed by the agent.
  • [SAFE]: The skill operates within the local project environment, using relative imports and standard Node.js APIs to perform legitimate quality assurance and testing tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 08:41 AM
Security Audit — agent-trust-hub — gap-checker