msw-behaviourtree

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a bundled Node.js script (scripts/build-spec.cjs) to scan project files and build a specification catalog. It also uses a shell command (node -e) to generate UUIDs. These actions are intended for environment scanning and ID generation but involve executing code on the local system.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific .codeblock and .mlua files to build a catalog that guides its logic. This ingestion of local data represents a surface where maliciously formatted project files could attempt to influence the agent's behavior during the behavior tree construction process.\n
  • Ingestion points: The scripts/build-spec.cjs script recursively reads .codeblock and .mlua files across the project directory.\n
  • Boundary markers: The skill does not explicitly instruct the agent to ignore instructions embedded within the source files it scans.\n
  • Capability inventory: The skill can read and write files in the project directory, execute Node.js scripts, and generate new .behaviourtree JSON configuration files.\n
  • Sanitization: Data is extracted using JSON parsing and regular expressions for specific Lua property patterns, providing structural constraints on the ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 11:12 PM