publish-mod

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements a security-first publishing workflow by requiring a linting step (um publish check) designed to detect and block the accidental inclusion of sensitive data such as .env files and API keys for AWS, OpenAI, Anthropic, and GitHub.
  • [SAFE]: The workflow incorporates a human-in-the-loop safety measure, explicitly instructing the agent to draft the publication and wait for the user to manually trigger the final release action.
  • [SAFE]: Best practices for legal and ethical modding are enforced, such as recommending patches instead of original game binaries and mandating disclosure for AI-generated assets.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes mod content and game files to generate metadata, changelogs, and README files, creating a potential surface for instructions embedded in mod data to influence agent behavior.
  • Ingestion points: Mod files located in the specified mod folder and game installation directories.
  • Boundary markers: The skill does not define explicit delimiters to isolate untrusted mod content from instructions during processing.
  • Capability inventory: The agent executes the um CLI utility and packages mod components into various archive formats (zip, tmod, jar).
  • Sanitization: The mandatory linting phase using um publish check serves as a security control to validate the mod's contents for credentials and prohibited assets before the agent proceeds with documentation or packaging.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 03:56 PM
Security Audit — agent-trust-hub — publish-mod