game-narrative
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input and existing game setting files to drive a collaborative narrative design pipeline.- Ingestion points: User input extracted during Phase 1 (genre, tone, scale) and optional user-provided files saved to the _workspace/ directory.- Boundary markers: The skill does not define explicit delimiters or instructions for agents to isolate potentially malicious prompts embedded within user-provided story data.- Capability inventory: Limited to file system writing within the project root (_workspace/ directory) and inter-agent communication via SendMessage and Task management. No remote code execution or external network exfiltration capabilities were identified.- Sanitization: The orchestrator instructions do not specify any validation, filtering, or escaping steps for user-supplied narrative content or uploaded setting files.
Audit Metadata