setup-engine
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill follows its stated purpose without incorporating malicious logic, obfuscation, or unauthorized credential access.
- [EXTERNAL_DOWNLOADS]: The skill utilizes
WebSearchandWebFetchto identify the latest stable versions of game engines and to retrieve technical documentation. This is an intended functional requirement for maintaining up-to-date environment configurations. - [DATA_EXPOSURE]: The skill reads project configuration files, specifically
CLAUDE.mdandgame-concept.md, to determine the appropriate engine and versioning required for the user's project. - [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it ingests untrusted data from the web (such as third-party migration guides) and stores it in the project's documentation files, which are later imported into the agent's context.
- Ingestion points: WebFetch operations described in Step 7 of
SKILL.mdfor migration and upgrade guides. - Boundary markers: Absent; the fetched content is written to markdown files without specific isolation markers or instructions to ignore embedded commands.
- Capability inventory: The skill uses
Write,Edit,WebSearch, andWebFetchtools. - Sanitization: No explicit sanitization or validation of the fetched remote content is performed before it is written to the local filesystem.
Audit Metadata