balance-check
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the
!syntax in its header to execute a shell command (yaml-helper.sh) when the skill is loaded. This is used to resolve configuration keys for automation modes. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources which represents a potential injection surface.
- Ingestion points: Reads game data and design documents from
assets/data/,design/balance/,design/registry/entities.yaml, anddesign/gdd/(SKILL.md). - Boundary markers: None explicitly defined to delimit data from instructions.
- Capability inventory: Uses
Writeto generate reports andAskUserQuestionto interact with the user (SKILL.md). - Sanitization: No specific sanitization or escaping of the ingested data is mentioned before processing.
Audit Metadata