localize
Warn
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill employs the
!commandsyntax to execute a shell script automatically when the skill is loaded into the agent's context. Evidence:!bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys automation. The command uses directory traversal (../../) to execute a script located outside the specific skill folder. The frontmatter also explicitly configures the Bash tool to allow this traversal pattern.- [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection as it reads and processes content from various untrusted external sources. Ingestion points: The skill reads source code files (duringscanandextract), game design documents (design/gdd/), and narrative files (design/narrative/). Boundary markers: No specific delimiters or safety instructions are defined to isolate data from these files. Capability inventory: The skill possessesBash,Write, andAgenttools, which could be misused if instructions are injected via the processed files. Sanitization: There is no evidence of sanitization or content validation for the ingested data.
Audit Metadata