msw-behaviourtree
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a bundled Node.js script (
scripts/build-spec.cjs) to scan project files and build a specification catalog. It also uses a shell command (node -e) to generate UUIDs. These actions are intended for environment scanning and ID generation but involve executing code on the local system.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific.codeblockand.mluafiles to build a catalog that guides its logic. This ingestion of local data represents a surface where maliciously formatted project files could attempt to influence the agent's behavior during the behavior tree construction process.\n - Ingestion points: The
scripts/build-spec.cjsscript recursively reads.codeblockand.mluafiles across the project directory.\n - Boundary markers: The skill does not explicitly instruct the agent to ignore instructions embedded within the source files it scans.\n
- Capability inventory: The skill can read and write files in the project directory, execute Node.js scripts, and generate new
.behaviourtreeJSON configuration files.\n - Sanitization: Data is extracted using JSON parsing and regular expressions for specific Lua property patterns, providing structural constraints on the ingested data.
Audit Metadata