balance-check

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the ! syntax in its header to execute a shell command (yaml-helper.sh) when the skill is loaded. This is used to resolve configuration keys for automation modes.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources which represents a potential injection surface.
  • Ingestion points: Reads game data and design documents from assets/data/, design/balance/, design/registry/entities.yaml, and design/gdd/ (SKILL.md).
  • Boundary markers: None explicitly defined to delimit data from instructions.
  • Capability inventory: Uses Write to generate reports and AskUserQuestion to interact with the user (SKILL.md).
  • Sanitization: No specific sanitization or escaping of the ingested data is mentioned before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 04:23 PM
Security Audit — agent-trust-hub — balance-check