prototype
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from user arguments and local project files to generate code and reports. This presents a vulnerability surface where malicious instructions embedded in design documents could influence agent behavior.
- Ingestion points: The
[concept-description]argument, as well as the filesdesign/gdd/game-concept.md,CLAUDE.md, and.claude/docs/technical-preferences.md(read in Phases 1 and 2). - Boundary markers: The skill does not employ specific delimiters or instructions for the agent to ignore potentially embedded commands within the ingested project files.
- Capability inventory: The skill utilizes
Bash,Write,Edit, andTask(which spawns thecreative-directoragent in Phase 8). These tools provide significant capabilities that could be misused if the agent obeys instructions injected into the context from the input files. - Sanitization: The skill lacks explicit sanitization, validation, or filtering of the content read from external files before using it to generate implementation code or summary reports.
Audit Metadata