team-level

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill performs standard file operations and task delegation within a local project environment.
  • [DATA_EXPOSURE]: The skill reads game design documents from the design/ directory to gather context. This behavior is consistent with the skill's stated purpose and does not involve access to sensitive system files, environment variables, or credentials.
  • [PROMPT_INJECTION]: The skill is a surface for indirect prompt injection as it reads existing documentation (e.g., design/gdd/game-concept.md) and interpolates the content into subagent prompts. However, the risk is mitigated by the inclusion of mandatory AskUserQuestion checkpoints for user approval before moving between steps.
  • [COMMAND_EXECUTION]: Although the skill lists Bash in its allowed tools, the instructions do not invoke any shell commands for system modification or network access, focusing instead on orchestration via the Task tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:11 PM
Security Audit — agent-trust-hub — team-level