building-maps
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided inputs such as 'spacious', 'western', or 'cool' to generate 3D environments. While it includes a mandatory checklist and 'thinking' block to validate and clarify vague modifiers, the lack of robust sanitization or strict schema enforcement for these natural language inputs introduces a runtime surface for potential indirect prompt injection during the generation of Lua code for Roblox. This is classified as LOW severity as it relates to the processing of untrusted data through an LLM reasoning step before code execution.
Audit Metadata