smash-and-clash-cli
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to drive a command-line interface, instructing the agent to execute shell commands like
smashandclash start,smashandclash move, andsmashandclash stateto interact with a game environment. - [EXTERNAL_DOWNLOADS]: The instructions describe fetching and running the tool using
npx smashandclash. This pattern involves downloading an external package from the npm registry at runtime. - [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection because the agent is instructed to read and act upon data retrieved from the CLI, which includes external game state and player information.
- Ingestion points: The agent ingests data from
smashandclash state(specificallylegalMoves) andsmashandclash duels(listing waiting players). Found in:SKILL.md. - Boundary markers: None. There are no specific instructions or delimiters provided to ensure the agent treats the game data as untrusted or ignores potential instructions contained within fields like move names or player handles.
- Capability inventory: The agent is authorized to execute shell commands (the
smashandclashCLI) and report status/results back to the user. Found in:SKILL.md. - Sanitization: The skill does not define any sanitization, validation, or filtering logic for the data returned by the game commands before the agent processes it.
Audit Metadata