game-analytics-platform-computer-vision
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The Spring Boot backend orchestrates Python AI processes using the
ProcessBuilderclass. It dynamically constructs script paths using a game identifier (games/exe_{id}.py). While the provided Java controller signature uses a typed integer, the pattern of executing local filesystem scripts based on external identifiers is a security-sensitive operation that requires strict input validation to prevent unintended process execution. - [DYNAMIC_EXECUTION]: The platform relies on runtime execution of Python scripts managed by a Java service. It builds execution paths at runtime based on the detected operating system (e.g.,
venv\\Scripts\\python.exevsvenv/bin/python) and user-selected game configurations. This dynamic execution model is central to the skill's functionality but increases the complexity of the execution environment. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data via real-time webcam video streams. This data is analyzed to generate workout metrics (reps, angles, timestamps) which are exported to CSV files. If an AI agent or secondary analysis tool subsequently reads these files, they could serve as a vector for indirect prompt injection if the data values are manipulated to contain instructions.
- Ingestion points: Video frames captured via
cv2.VideoCapture(0)in game scripts. - Boundary markers: No specific delimiters or safety warnings are present in the exported CSV metrics.
- Capability inventory: The system can start processes via
ProcessBuilderand write files viapandas.to_csv. - Sanitization: Input validation is focused on vision logic (e.g., angle calculations) rather than instruction filtering.
- [EXTERNAL_DOWNLOADS]: The platform fetches several industry-standard AI and data processing libraries during installation, including YOLO v8, MediaPipe, OpenCV, and Pandas. Additionally, the
ultralyticslibrary is configured to automatically download pre-trained YOLO models (e.g.,yolov8n.pt) if they are not found locally. These resources originate from well-known technology organizations and official registries.
Audit Metadata