specialist-game-development-unreal-engine-unreal-systems-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill is composed entirely of markdown instructions and a tool call to spawn a sub-agent. It does not contain any scripts, binaries, or configuration files that execute code on the host system.
  • [SAFE]: The skill's primary function is to delegate tasks to a technical specialist. No patterns of prompt injection, data exfiltration, or obfuscation were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill interpolates untrusted user input directly into a sub-agent prompt using the {the user's question} variable. While this is a common ingestion point for indirect instructions, the skill lacks boundary markers (e.g., delimiters) to separate the system instructions from the user-provided content. However, given the limited capability of this skill and the absence of high-risk tools, this is considered a best-practice violation rather than a direct threat.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 08:50 PM
Security Audit — agent-trust-hub — specialist-game-development-unreal-engine-unreal-systems-engineer