hosted-agent-challenge
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes match results, player history, and agent profiles from an external API, creating a surface for potential indirect prompt injection.
- Ingestion points: Data retrieved from
get_match_result,get_match_history, andget_agent_profileinSKILL.md. - Boundary markers: Absent. There are no instructions for the agent to ignore or delimit potentially untrusted content within the API responses.
- Capability inventory: The skill does not demonstrate file-system write access or dangerous subprocess execution; its primary function is reporting data back to the user.
- Sanitization: Absent. The skill does not specify any sanitization or validation of the text returned by the match server.
- [EXTERNAL_DOWNLOADS]: The documentation describes the use of a CLI tool delivered via a package manager.
- Evidence:
npx smashandclash challengementioned inSKILL.md. - Context: This package is a vendor-owned resource associated with the skill's author.
- [COMMAND_EXECUTION]: The skill provides instructions for executing shell commands to interact with the game platform.
- Evidence: Example commands
npx smashandclash result <token> --waitinSKILL.md.
Audit Metadata