game-audio-engineer

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes dynamic context injection to execute shell cat commands during the skill loading phase. These commands are used to incorporate content from internal project files, such as shared protocols (e.g., skills/_shared/protocols/ux-protocol.md) and configuration settings (.production-grade.yaml). This ensures the agent has access to modular guidelines but constitutes execution of shell commands at load time.- [PROMPT_INJECTION]: The skill architecture presents a surface for indirect prompt injection because it is designed to ingest and process data from external sources (Game Designer feedback specs, Narrative Designer character descriptions) to generate design documentation.
  • Ingestion points: SKILL.md identifies inputs from Game Designer, Level Designer, and Narrative Designer as critical data sources.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the instructions to protect against instructions hidden within the design specs.
  • Capability inventory: The skill performs extensive file-writing operations to create the .forgewright/game-audio-engineer/ directory structure.
  • Sanitization: There is no documentation of validation or sanitization for the inputs before they are used to generate the output files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 07:28 PM
Security Audit — agent-trust-hub — game-audio-engineer