godot-animation-studio

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were detected. The skill's behavior and provided GDScript code are appropriate for its role as a resource management utility for the Godot Engine.
  • [INDIRECT_PROMPT_INJECTION]: The skill's asset processing logic represents an attack surface for indirect prompt injection via untrusted files. Ingestion points: The process_sprite_sheets function in SKILL.md reads files from a user-provided directory path. Boundary markers: The skill does not define specific delimiters or instructions to the agent to ignore potentially malicious content within processed assets. Capability inventory: The skill utilizes DirAccess for directory traversal, load() for asset ingestion, and ResourceSaver.save() for writing resource files in SKILL.md. Sanitization: The provided GDScript examples do not implement explicit validation for input paths or filenames.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 11:45 AM
Security Audit — agent-trust-hub — godot-animation-studio