smash-and-clash-webmcp

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data to determine game moves and display player information.
  • Ingestion points: Data is retrieved via get_game_state (board state and hand) and get_profile (player name and rating) from the smashandclash.in domain.
  • Boundary markers: The skill instructions do not specify explicit delimiters or warnings to ignore potentially malicious instructions embedded in game data.
  • Capability inventory: The agent can perform actions such as play_move, start_match, and open_page based on the ingested state.
  • Sanitization: No specific sanitization or validation of the game state strings is described, though moves are restricted to those found in legalMoves.
  • [SAFE]: The skill's functionality is consistent with its stated purpose of providing a game interface. All external references are to the author's own domain (smashandclash.in), representing standard vendor functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 06:14 PM
Security Audit — agent-trust-hub — smash-and-clash-webmcp