unreal-engineer

Pass

Audited by Gen Agent Trust Hub on May 4, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the !command syntax to load context from local files like .production-grade.yaml and .forgewright/settings.md at startup. These operations are limited to reading specific local paths for configuration and do not involve network exfiltration or access to sensitive system directories.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection. 1. Ingestion points: Processes project data from .production-grade.yaml and .forgewright/ codebase files. 2. Boundary markers: The skill does not define clear delimiters or instructions to ignore potential commands within the ingested content. 3. Capability inventory: The skill is capable of writing complex C++ and Blueprint logic and references executing build scripts like GenerateProjectFiles.bat. 4. Sanitization: No sanitization or validation mechanisms are described for the external content it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
May 4, 2026, 01:58 PM
Security Audit — agent-trust-hub — unreal-engineer