smash-and-clash-setup

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill mentions using npx smashandclash and installing @smashandclash/sdk via npm. These packages originate from the official vendor's registry scope and are intended for game interaction and development.
  • [COMMAND_EXECUTION]: The instructions suggest executing npx smashandclash to launch the game interface within the user's terminal environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data by calling get_rules from the vendor's API at https://www.smashandclash.in/api/mcp to inform the agent's understanding of the game logic.
  • Ingestion points: External rules fetched from smashandclash.in via the get_rules tool.
  • Capability inventory: Access to tools for game state management and challenge links.
  • Boundary markers: None present.
  • Sanitization: None present.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 06:14 PM
Security Audit — agent-trust-hub — smash-and-clash-setup