team-level
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill demonstrates an attack surface for indirect prompt injection by gathering content from multiple local files and passing it to sub-agents as context.
- Ingestion points: The orchestrator reads data from
production/review-mode.txt,design/gdd/game-concept.md,design/gdd/game-pillars.md, and directoriesdesign/levels/,design/narrative/, anddesign/art/as described in Phase 0 and the context gathering sections. - Boundary markers: No delimiters or explicit instructions to ignore embedded commands are specified for the context provided to sub-agents.
- Capability inventory: The orchestrator and sub-agents have access to tools including
Bash,Write,Edit, andTask, enabling potential code execution or file modification based on ingested data. - Sanitization: The instructions do not define any sanitization, filtering, or validation protocols for the ingested file content.
Audit Metadata