roblox-launch-campaign

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill establishes a high-standard, structured workflow for Roblox development without introducing malicious patterns. It focuses on using legitimate tools like Rojo, Jest (via Luau), and the Model Context Protocol (MCP) for Studio automation.
  • [COMMAND_EXECUTION]: The skill provides standard development commands (e.g., npm run build:deps, wally-package-types, rojo serve). These are restricted to local development environments and are common in the Roblox/Luau ecosystem.
  • [REMOTE_CODE_EXECUTION]: While the skill mentions and uses the roblox-testing plugin and MCP, these are established tools for AI-driven development in Roblox. The instructions emphasize local execution and testing rather than downloading and running unverified remote code.
  • [PROMPT_INJECTION]: The skill defines 'hard rules' for agent behavior (e.g., forbidding rblxsync run for agents, requiring evidence-based tuning). These are safety constraints rather than attempts to bypass platform-level security filters.
  • [DATA_EXFILTRATION]: There are no patterns detected that attempt to access or exfiltrate sensitive data such as .env files, SSH keys, or cloud credentials. All network operations are directed towards local Studio MCP servers or standard package registries (Wally).
  • [PRIVILEGE_ESCALATION]: The skill does not request or use administrative privileges (e.g., sudo). It explicitly fences off 'owner-only' tasks (like real purchases or production deployments) to ensure the AI operates within a low-privilege boundary.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 04:08 AM
Security Audit — agent-trust-hub — roblox-launch-campaign