hosted-agent-challenge

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes match results, player history, and agent profiles from an external API, creating a surface for potential indirect prompt injection.
  • Ingestion points: Data retrieved from get_match_result, get_match_history, and get_agent_profile in SKILL.md.
  • Boundary markers: Absent. There are no instructions for the agent to ignore or delimit potentially untrusted content within the API responses.
  • Capability inventory: The skill does not demonstrate file-system write access or dangerous subprocess execution; its primary function is reporting data back to the user.
  • Sanitization: Absent. The skill does not specify any sanitization or validation of the text returned by the match server.
  • [EXTERNAL_DOWNLOADS]: The documentation describes the use of a CLI tool delivered via a package manager.
  • Evidence: npx smashandclash challenge mentioned in SKILL.md.
  • Context: This package is a vendor-owned resource associated with the skill's author.
  • [COMMAND_EXECUTION]: The skill provides instructions for executing shell commands to interact with the game platform.
  • Evidence: Example commands npx smashandclash result <token> --wait in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 06:14 PM
Security Audit — agent-trust-hub — hosted-agent-challenge