unreal-engineer
Pass
Audited by Gen Agent Trust Hub on May 4, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the !command syntax to load context from local files like .production-grade.yaml and .forgewright/settings.md at startup. These operations are limited to reading specific local paths for configuration and do not involve network exfiltration or access to sensitive system directories.
- [INDIRECT_PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection. 1. Ingestion points: Processes project data from .production-grade.yaml and .forgewright/ codebase files. 2. Boundary markers: The skill does not define clear delimiters or instructions to ignore potential commands within the ingested content. 3. Capability inventory: The skill is capable of writing complex C++ and Blueprint logic and references executing build scripts like GenerateProjectFiles.bat. 4. Sanitization: No sanitization or validation mechanisms are described for the external content it processes.
Audit Metadata