godot-multiplayer

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes dynamic context injection (!command) in SKILL.md to execute shell commands when the skill is loaded. These commands (cat) are used to integrate shared protocol files (e.g., ux-protocol.md, task-validator.md) and local configuration (.production-grade.yaml) into the agent's context. This is a standard mechanism for modularity in specific agent environments and targets internal project resources.
  • [PROMPT_INJECTION]: The skill dynamically ingests content from multiple local files (protocols and configuration) via shell commands. This creates an ingestion surface for indirect prompt injection, as the agent context is populated with data from external files without explicit boundary markers or sanitation, although the content sources appear to be internal to the project repository.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — godot-multiplayer