gamedev-godot

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation and management of Godot projects, which involves the ingestion of external source code, scene definitions, and assets. This creates an attack surface where instructions could be embedded in project data processed by the agent.
  • Ingestion points: The skill operates on Godot project directories, referencing project.godot, .tscn (scenes), .gd (GDScript), and .tres/.res (resources) files as described in SKILL.md and references/scenes-and-nodes.md.
  • Boundary markers: There are no explicit instructions for the AI to treat project content as untrusted data beyond general engine behavior.
  • Capability inventory: The skill utilizes shell command execution for build automation (godot --headless --export-release in SKILL.md) and allows for code execution within the Godot editor context through @tool scripts as detailed in references/gdscript-and-architecture.md.
  • Sanitization: The skill provides proactive security guidance in references/rendering-and-export.md, warning users to avoid ResourceSaver for untrusted data and suggesting JSON as a safer alternative to mitigate deserialization-based RCE.
  • [COMMAND_EXECUTION]: The skill instructs the agent on how to use the Godot CLI for headless exports, which involves executing system commands.
  • Evidence: SKILL.md and references/rendering-and-export.md document the use of godot --headless --export-release for CI/CD pipelines.
  • [DYNAMIC_EXECUTION]: The skill describes techniques for executing code dynamically within the engine environment.
  • Evidence: references/gdscript-and-architecture.md covers the use of @tool to run scripts within the editor. The skill also correctly identifies and warns against the dynamic code execution risk in Godot's resource loading system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — gamedev-godot