smash-and-clash-cli

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to drive a command-line interface, instructing the agent to execute shell commands like smashandclash start, smashandclash move, and smashandclash state to interact with a game environment.
  • [EXTERNAL_DOWNLOADS]: The instructions describe fetching and running the tool using npx smashandclash. This pattern involves downloading an external package from the npm registry at runtime.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection because the agent is instructed to read and act upon data retrieved from the CLI, which includes external game state and player information.
  • Ingestion points: The agent ingests data from smashandclash state (specifically legalMoves) and smashandclash duels (listing waiting players). Found in: SKILL.md.
  • Boundary markers: None. There are no specific instructions or delimiters provided to ensure the agent treats the game data as untrusted or ignores potential instructions contained within fields like move names or player handles.
  • Capability inventory: The agent is authorized to execute shell commands (the smashandclash CLI) and report status/results back to the user. Found in: SKILL.md.
  • Sanitization: The skill does not define any sanitization, validation, or filtering logic for the data returned by the game commands before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 06:15 PM
Security Audit — agent-trust-hub — smash-and-clash-cli