localize

Warn

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill employs the !command syntax to execute a shell script automatically when the skill is loaded into the agent's context. Evidence: !bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys automation. The command uses directory traversal (../../) to execute a script located outside the specific skill folder. The frontmatter also explicitly configures the Bash tool to allow this traversal pattern.- [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection as it reads and processes content from various untrusted external sources. Ingestion points: The skill reads source code files (during scan and extract), game design documents (design/gdd/), and narrative files (design/narrative/). Boundary markers: No specific delimiters or safety instructions are defined to isolate data from these files. Capability inventory: The skill possesses Bash, Write, and Agent tools, which could be misused if instructions are injected via the processed files. Sanitization: There is no evidence of sanitization or content validation for the ingested data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 30, 2026, 05:58 PM
Security Audit — agent-trust-hub — localize