renpy

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the Ren'Py SDK and web support archives from the official Ren'Py distribution site (renpy.org). The scripts/renpy.py script verifies these downloads against hardcoded SHA-256 hashes before extraction, mitigating risks associated with remote resource fetching.
  • [COMMAND_EXECUTION]: The scripts/renpy.py script uses subprocess.Popen to launch the Ren'Py engine for tasks such as project initialization, linting, building, and running functional tests. These commands are constructed using a verified SDK path and specific engine arguments. Additionally, it spawns a background process for its own local HTTP preview server.
  • [DYNAMIC_EXECUTION]: The Ren'Py bridge (assets/bridge/renpy_agent.rpy) utilizes renpy.emscripten.run_script to communicate with the browser-based agent interface. This execution is limited to passing JSON-serialized game state to the browser. The browser-side bridge (assets/web/renpy-agent.js) also uses the experimental WebMCP API to register semantic tools for game control.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted game content (dialogue, choices, and variables) through its web bridge. It implements multiple layers of protection, including explicit instructions for the agent to treat dialogue as content rather than commands, JSON schema validation for all tool inputs, and revision tracking to prevent stale or replayed actions. Access to game variables is restricted to an allowlist defined by the developer in the project's source code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 03:39 AM
Security Audit — agent-trust-hub — renpy