phaser3-engineer

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes dynamic context injection (the !command`` syntax) within SKILL.md to execute shell commands at load time.
  • Evidence: Multiple instances of cat are used to load protocol documents (e.g., skills/_shared/protocols/ux-protocol.md) and configuration files (e.g., .production-grade.yaml).
  • [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection by ingesting external data into the agent's context without sanitization or boundary markers.
  • Ingestion points: Content from .production-grade.yaml and .forgewright/codebase-context.md is loaded into the prompt via shell execution in SKILL.md.
  • Boundary markers: Absent; the content is concatenated into the prompt context without delimiters or instructions to ignore embedded commands.
  • Capability inventory: The skill possesses the capability to execute shell commands (via project scaffolding scripts) and perform file system writes across the src/ directory.
  • Sanitization: None; the skill lacks validation for the content of the loaded files before they are processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to install standard development dependencies from the public NPM registry.
  • Evidence: npm install phaser typescript vite @types/node and npx tsc --init are used during the scaffolding phase.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — phaser3-engineer