cli-anything-slay-the-spire-ii

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to clone a code repository from the author's GitHub account (github.com/HKUDS/CLI-Anything.git) to obtain the CLI and bridge mod.
  • [COMMAND_EXECUTION]: The installation process involves executing shell scripts (build.sh and install_bridge.sh) to compile and install a .NET 9 plugin into the game's data directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an ingestion surface for potentially untrusted data by reading game state from a local HTTP API.
  • Ingestion points: The state and raw-state commands in SKILL.md fetch JSON data from localhost:15526.
  • Boundary markers: No explicit boundary markers or directives to ignore embedded instructions are used when processing the game state.
  • Capability inventory: The skill can execute complex game actions, including card play and navigation, as well as arbitrary actions via the action command.
  • Sanitization: The instructions do not describe any sanitization or validation of the ingested game state before it is interpreted by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:21 PM