phaser3-engineer
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes dynamic context injection (the
!command`` syntax) withinSKILL.mdto execute shell commands at load time. - Evidence: Multiple instances of
catare used to load protocol documents (e.g.,skills/_shared/protocols/ux-protocol.md) and configuration files (e.g.,.production-grade.yaml). - [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection by ingesting external data into the agent's context without sanitization or boundary markers.
- Ingestion points: Content from
.production-grade.yamland.forgewright/codebase-context.mdis loaded into the prompt via shell execution inSKILL.md. - Boundary markers: Absent; the content is concatenated into the prompt context without delimiters or instructions to ignore embedded commands.
- Capability inventory: The skill possesses the capability to execute shell commands (via project scaffolding scripts) and perform file system writes across the
src/directory. - Sanitization: None; the skill lacks validation for the content of the loaded files before they are processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to install standard development dependencies from the public NPM registry.
- Evidence:
npm install phaser typescript vite @types/nodeandnpx tsc --initare used during the scaffolding phase.
Audit Metadata