mod-any-game

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the um toolkit from the author's GitHub repository (rehan-remade/universal-modder) using package managers like uv or pipx.
  • [COMMAND_EXECUTION]: The agent uses the um toolkit to execute a wide range of system commands, including managing game processes, launching executables, and performing input automation (um win drive) to drive the game's interface.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the game's execution environment, which could potentially host malicious instructions.
  • Ingestion points: The agent is instructed to read various game logs (e.g., client.log, Player.log, UE4SS.log) and analyze screenshots (um win shot) to verify mod functionality in SKILL.md and the engine references.
  • Boundary markers: No specific delimiting markers or instructions are provided to help the agent distinguish between its own logic and data found in external logs or assets.
  • Capability inventory: The agent possesses powerful capabilities, including the ability to drive keyboard/mouse input, modify the file system for mod creation, and execute shell commands via the um CLI.
  • Sanitization: The instructions do not include steps for sanitizing, escaping, or validating the content of game logs or metadata before the agent processes them.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 05:17 PM
Security Audit — agent-trust-hub — mod-any-game