game-review

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data, which introduces a surface for indirect prompt injection. \n
  • Ingestion points: The skill is designed to read playtest notes, README files, store copy, and various build artifacts as specified in SKILL.md and references/evidence-and-release.md.\n
  • Boundary markers: The instructions do not include explicit delimiters or warnings to ignore instructions embedded within the processed evidence artifacts.\n
  • Capability inventory: The skill utilizes "mechanical checks," which are described in SKILL.md and references/evidence-and-release.md as commands or tests used to verify technical conditions.\n
  • Sanitization: There is no provision for sanitizing or escaping the content retrieved from external files before it is interpolated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 10:12 AM
Security Audit — agent-trust-hub — game-review