playtest-report

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the ! syntax to execute a shell command during the skill loading phase: !bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys review_mode,automation. While the command is used for configuration resolution and targets a local script, this mechanism allows code execution outside of the standard interactive prompt cycle.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in Phase 2B, where it reads raw playtest notes from a user-provided path.
  • Ingestion points: Reads raw notes from a path specified in the analyze argument during Phase 2B.
  • Boundary markers: None identified; the skill instructions do not specify delimiters or instructions to ignore embedded commands within the notes.
  • Capability inventory: The skill has the ability to write files (Phase 4), spawn sub-agents using the Agent tool (Phase 3b), and execute specific local shell scripts via the restricted Bash tool.
  • Sanitization: No explicit sanitization or validation of the content of the playtest notes is described before it is used to populate templates or inform the Creative Director agent.
  • [COMMAND_EXECUTION]: The skill's configuration limits the Bash tool to a specific local script: bash "*/.claude/skills/playtest-report/../../hooks/yaml-helper.sh" resolve_config *. This is used to resolve project-specific configuration for review modes and automation levels.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:51 PM
Security Audit — agent-trust-hub — playtest-report