game-designer
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFE
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the shell execution syntax (e.g.,
!cat path/to/file) to load local configuration files and protocols into the agent's context. These operations are limited to the local filesystem within the skill's expected directory structure (e.g.,.forgewright/settings.md,skills/_shared/protocols/) and do not involve network requests, sensitive system directories, or the injection of unvalidated user arguments into the shell.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted user data in the form of game concepts and descriptions (Phase 1). While it lacks explicit boundary markers or sanitization instructions for this input, this is a standard functional requirement for a design-oriented skill and does not pose a significant risk given the skill's limited capability to perform high-privilege actions.
Audit Metadata