flame-game-dev

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides architectures for game systems that ingest and process structured data from external JSON and Tiled (.tmx) files. This creates a surface for indirect prompt injection.
  • Ingestion points: Data enters the context via jsonDecode and Tiled object parsing in files such as flame-systems/references/inventory.md (ItemDatabase), flame-systems/references/quest.md (QuestManager), and flame-templates/references/platformer.md (Level loading).
  • Boundary markers: The provided code templates do not define delimiters or explicit instructions for the AI to ignore embedded natural language instructions within the data fields.
  • Capability inventory: The skill documents capabilities including file system modification (File.writeAsString), networking (WebSocketChannel), and cloud storage (FirebaseFirestore).
  • Sanitization: The reference implementations lack validation or sanitization logic to detect or neutralize malicious instructions that could be embedded in data files provided by external sources or users during the game development lifecycle.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:01 AM
Security Audit — agent-trust-hub — flame-game-dev