play-smash-and-clash

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes game state data and move lists from an external game server, which represents a potential attack surface for indirect prompt injection.
  • Ingestion points: The agent receives structured data (board view, legal moves, and game status) from tools such as start_game, play_move, and get_game defined in SKILL.md.
  • Boundary markers: None explicitly defined for the tool outputs.
  • Capability inventory: The skill's capabilities are limited to game-specific actions such as submitting moves, resigning, or creating duels through the MCP server.
  • Sanitization: The instructions mitigate risk by explicitly directing the agent to only use move strings provided by the server in the legalMoves field and to never invent its own moves.
  • [EXTERNAL_DOWNLOADS]: The skill mentions external tools and libraries associated with the game author.
  • The documentation references the @smashandclash/sdk NPM package and the npx smashandclash CLI tool. These are provided as informational resources for developers and users.
  • [CREDENTIALS_UNSAFE]: The skill describes the use of a player_token for session management.
  • The instructions correctly identify the token as sensitive information and provide explicit security guidance to the agent: "Keep it, and never show it to anyone else."
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 06:14 PM
Security Audit — agent-trust-hub — play-smash-and-clash