prototype

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from user arguments and local project files to generate code and reports. This presents a vulnerability surface where malicious instructions embedded in design documents could influence agent behavior.
  • Ingestion points: The [concept-description] argument, as well as the files design/gdd/game-concept.md, CLAUDE.md, and .claude/docs/technical-preferences.md (read in Phases 1 and 2).
  • Boundary markers: The skill does not employ specific delimiters or instructions for the agent to ignore potentially embedded commands within the ingested project files.
  • Capability inventory: The skill utilizes Bash, Write, Edit, and Task (which spawns the creative-director agent in Phase 8). These tools provide significant capabilities that could be misused if the agent obeys instructions injected into the context from the input files.
  • Sanitization: The skill lacks explicit sanitization, validation, or filtering of the content read from external files before using it to generate implementation code or summary reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 09:12 AM
Security Audit — agent-trust-hub — prototype