prompt-to-game
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided natural language prompts to generate game code, which presents a surface for indirect prompt injection where instructions could be embedded in the game descriptions.
- Ingestion points: User prompts describing game mechanics, themes, and structures entering the agent context via the 'vibe coding' workflow.
- Boundary markers: The
SKILL.mdfile provides explicit instructions for the agent to ground all responses in the specific reference files (patterns.md,sharp_edges.md,validations.md), creating a constrained operational context. - Capability inventory: The skill is focused on code generation for external game frameworks (Phaser 3, Godot, Three.js). The skill does not request or utilize tools for direct shell execution or network operations in the provided metadata.
- Sanitization: The skill contains a robust
references/validations.mdfile that defines strict rules to detect and prevent common AI security failures such aseval()usage, hardcoded API keys, andinnerHTMLvulnerabilities. - [SAFE]: The skill includes code snippets demonstrating insecure patterns (e.g., hardcoded secrets and
eval()calls) and remote dependencies (e.g., Phaser, Three.js); however, these are used exclusively for educational purposes in the context of 'bad examples' or for defining validation rules to improve security, not for execution.
Audit Metadata