randroid-game-feel
Warn
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill contains a PowerShell utility designed to launch and monitor native Windows executables.
- Evidence:
scripts/native-probe.ps1accepts an executable path via the-Exeparameter and runs it usingStart-Process. - [DYNAMIC_EXECUTION]: The native diagnostic script utilizes runtime compilation to interface with low-level system functions.
- Evidence:
scripts/native-probe.ps1usesAdd-Type -TypeDefinitionto compile C# source code that importsuser32.dllandkernel32.dllfor window management and simulated input events. - [INDIRECT_PROMPT_INJECTION]: The browser-based diagnostic tool processes content from external websites, creating a potential vector for indirect instructions.
- Ingestion points:
scripts/game-probe.mjsuses Playwright to visit external URLs and extract UI labels and text content via theAUDITfunction. - Boundary markers: The skill does not implement delimiters or explicit 'ignore instructions' warnings when processing data from the browser probe.
- Capability inventory: The skill has the ability to write files to the disk (
report.json), execute local processes via PowerShell, and perform network requests. - Sanitization: There is no evidence of sanitization or filtering for the textual content retrieved from external game pages.
- [EXTERNAL_DOWNLOADS]: The skill's browser diagnostic tool performs network operations to external locations.
- Evidence:
scripts/game-probe.mjsusespage.goto(options.url)to load user-provided web addresses for analysis.
Audit Metadata