team-level
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill performs standard file operations and task delegation within a local project environment.
- [DATA_EXPOSURE]: The skill reads game design documents from the
design/directory to gather context. This behavior is consistent with the skill's stated purpose and does not involve access to sensitive system files, environment variables, or credentials. - [PROMPT_INJECTION]: The skill is a surface for indirect prompt injection as it reads existing documentation (e.g.,
design/gdd/game-concept.md) and interpolates the content into subagent prompts. However, the risk is mitigated by the inclusion of mandatoryAskUserQuestioncheckpoints for user approval before moving between steps. - [COMMAND_EXECUTION]: Although the skill lists
Bashin its allowed tools, the instructions do not invoke any shell commands for system modification or network access, focusing instead on orchestration via theTasktool.
Audit Metadata