randroid-game-feel

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains a PowerShell utility designed to launch and monitor native Windows executables.
  • Evidence: scripts/native-probe.ps1 accepts an executable path via the -Exe parameter and runs it using Start-Process.
  • [DYNAMIC_EXECUTION]: The native diagnostic script utilizes runtime compilation to interface with low-level system functions.
  • Evidence: scripts/native-probe.ps1 uses Add-Type -TypeDefinition to compile C# source code that imports user32.dll and kernel32.dll for window management and simulated input events.
  • [INDIRECT_PROMPT_INJECTION]: The browser-based diagnostic tool processes content from external websites, creating a potential vector for indirect instructions.
  • Ingestion points: scripts/game-probe.mjs uses Playwright to visit external URLs and extract UI labels and text content via the AUDIT function.
  • Boundary markers: The skill does not implement delimiters or explicit 'ignore instructions' warnings when processing data from the browser probe.
  • Capability inventory: The skill has the ability to write files to the disk (report.json), execute local processes via PowerShell, and perform network requests.
  • Sanitization: There is no evidence of sanitization or filtering for the textual content retrieved from external game pages.
  • [EXTERNAL_DOWNLOADS]: The skill's browser diagnostic tool performs network operations to external locations.
  • Evidence: scripts/game-probe.mjs uses page.goto(options.url) to load user-provided web addresses for analysis.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 11:21 PM