roblox-design-consultant

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed solely for requirement gathering through dialogue. It does not include any executable scripts or external dependencies.
  • [COMMAND_EXECUTION]: The skill contains explicit negative constraints to prevent the AI from generating code or invoking tools (e.g., "You NEVER write Roblox Lua code", "You NEVER call mcp__roblox__run_code"), which reduces the risk of accidental or malicious command execution.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes untrusted user input to generate a design brief, it has no access to sensitive capabilities like network requests, file writes, or system commands. This lack of access mitigates the risk of an indirect prompt injection attack being used to compromise the system.
  • [DATA_EXFILTRATION]: There are no network operations or access to sensitive local files (such as SSH keys or environment variables) within the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:52 AM
Security Audit — agent-trust-hub — roblox-design-consultant