publish-mod
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements a security-first publishing workflow by requiring a linting step (
um publish check) designed to detect and block the accidental inclusion of sensitive data such as .env files and API keys for AWS, OpenAI, Anthropic, and GitHub. - [SAFE]: The workflow incorporates a human-in-the-loop safety measure, explicitly instructing the agent to draft the publication and wait for the user to manually trigger the final release action.
- [SAFE]: Best practices for legal and ethical modding are enforced, such as recommending patches instead of original game binaries and mandating disclosure for AI-generated assets.
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes mod content and game files to generate metadata, changelogs, and README files, creating a potential surface for instructions embedded in mod data to influence agent behavior.
- Ingestion points: Mod files located in the specified mod folder and game installation directories.
- Boundary markers: The skill does not define explicit delimiters to isolate untrusted mod content from instructions during processing.
- Capability inventory: The agent executes the
umCLI utility and packages mod components into various archive formats (zip, tmod, jar). - Sanitization: The mandatory linting phase using
um publish checkserves as a security control to validate the mod's contents for credentials and prohibited assets before the agent proceeds with documentation or packaging.
Audit Metadata