play-smash-and-clash
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes game state data and move lists from an external game server, which represents a potential attack surface for indirect prompt injection.
- Ingestion points: The agent receives structured data (board view, legal moves, and game status) from tools such as
start_game,play_move, andget_gamedefined inSKILL.md. - Boundary markers: None explicitly defined for the tool outputs.
- Capability inventory: The skill's capabilities are limited to game-specific actions such as submitting moves, resigning, or creating duels through the MCP server.
- Sanitization: The instructions mitigate risk by explicitly directing the agent to only use move strings provided by the server in the
legalMovesfield and to never invent its own moves. - [EXTERNAL_DOWNLOADS]: The skill mentions external tools and libraries associated with the game author.
- The documentation references the
@smashandclash/sdkNPM package and thenpx smashandclashCLI tool. These are provided as informational resources for developers and users. - [CREDENTIALS_UNSAFE]: The skill describes the use of a
player_tokenfor session management. - The instructions correctly identify the token as sensitive information and provide explicit security guidance to the agent: "Keep it, and never show it to anyone else."
Audit Metadata