setup-engine

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill follows its stated purpose without incorporating malicious logic, obfuscation, or unauthorized credential access.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes WebSearch and WebFetch to identify the latest stable versions of game engines and to retrieve technical documentation. This is an intended functional requirement for maintaining up-to-date environment configurations.
  • [DATA_EXPOSURE]: The skill reads project configuration files, specifically CLAUDE.md and game-concept.md, to determine the appropriate engine and versioning required for the user's project.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it ingests untrusted data from the web (such as third-party migration guides) and stores it in the project's documentation files, which are later imported into the agent's context.
  • Ingestion points: WebFetch operations described in Step 7 of SKILL.md for migration and upgrade guides.
  • Boundary markers: Absent; the fetched content is written to markdown files without specific isolation markers or instructions to ignore embedded commands.
  • Capability inventory: The skill uses Write, Edit, WebSearch, and WebFetch tools.
  • Sanitization: No explicit sanitization or validation of the fetched remote content is performed before it is written to the local filesystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:11 PM
Security Audit — agent-trust-hub — setup-engine