godot-shader-developer
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by instructing the agent to ingest untrusted external data, such as 'Effect Designs', 'reference images', and 'reference videos', to generate shader and GDScript code.
- Ingestion points: The 'Effect Design' workflow stage explicitly takes reference images and videos as input.
- Boundary markers: The skill lacks instructions for the agent to use delimiters or to ignore potential instructions embedded within these external references.
- Capability inventory: The agent is authorized to generate complex GLSL shaders and GDScript '@tool' scripts which execute within the Godot editor environment.
- Sanitization: There is no requirement or guidance for the agent to validate or sanitize the contents of the generated code based on the source material.
Audit Metadata