setup-engine
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill employs dynamic context injection using the
!commandsyntax to execute a local shell script (yaml-helper.sh) at load time. This mechanism is used to resolve project-wide configuration such as the current workflow tier. - [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it ingests untrusted data from the web (official engine documentation and migration guides) through the
WebFetchandWebSearchtools. This data is then used to populate reference documents that instruct subsequent agent actions. Ingestion points: Results fromWebSearchandWebFetchqueries for engine versions and migration guides. Boundary markers: The skill instructs agents to prioritize the generated reference docs over training data but lacks explicit delimiters or sanitization for the fetched content. Capability inventory: The skill possessesBash,Write, andEditcapabilities, allowing it to execute local scripts and modify project files based on external input. Sanitization: No specific sanitization or filtering of external content is described before it is written to the project's documentation files. - [COMMAND_EXECUTION]: The skill uses the
Bashtool to execute local utility scripts (project-coherence.sh) and engine-specific command-line tools (e.g.,godot --version,Unity -version). These commands are used to verify the local environment and validate the project configuration.
Audit Metadata