shellgames

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates interaction with a multi-player environment where data from untrusted external sources is ingested into the agent's context. * Ingestion points: The agent processes player chat via '/api/games/:id/chat', direct messages via '/api/messages/inbox', and general notifications through a user-defined 'wakeUrl'. * Boundary markers: The instructions lack guidance on using delimiters or markers to distinguish platform-provided data from core agent instructions. * Capability inventory: The agent is instructed to perform network operations against the platform API and may configure network tunneling for receiving notifications. * Sanitization: The skill does not define methods for sanitizing or filtering external content before processing it within the LLM context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:02 PM