renpy
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the Ren'Py SDK and web support archives from the official Ren'Py distribution site (renpy.org). The
scripts/renpy.pyscript verifies these downloads against hardcoded SHA-256 hashes before extraction, mitigating risks associated with remote resource fetching. - [COMMAND_EXECUTION]: The
scripts/renpy.pyscript usessubprocess.Popento launch the Ren'Py engine for tasks such as project initialization, linting, building, and running functional tests. These commands are constructed using a verified SDK path and specific engine arguments. Additionally, it spawns a background process for its own local HTTP preview server. - [DYNAMIC_EXECUTION]: The Ren'Py bridge (
assets/bridge/renpy_agent.rpy) utilizesrenpy.emscripten.run_scriptto communicate with the browser-based agent interface. This execution is limited to passing JSON-serialized game state to the browser. The browser-side bridge (assets/web/renpy-agent.js) also uses the experimental WebMCP API to register semantic tools for game control. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted game content (dialogue, choices, and variables) through its web bridge. It implements multiple layers of protection, including explicit instructions for the agent to treat dialogue as content rather than commands, JSON schema validation for all tool inputs, and revision tracking to prevent stale or replayed actions. Access to game variables is restricted to an allowlist defined by the developer in the project's source code.
Audit Metadata