worldos-simulation-play

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read and interpret narrative outputs and player-visible state changes from the WorldOS platform. While these are external inputs, the skill limits the agent's actions to specific platform tools and emphasizes manual verification of results. Ingestion points include results from play_owned_save_turn and get_owned_save_turns. Boundary markers are present in the form of instructions to separate "natural player interactions" from "engine operations or state paths." Capability inventory is restricted to the specific worldos-simulation-play MCP tools. Sanitization is not explicitly defined in the instructions, relying on platform-level controls.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill explicitly forbids requesting access tokens in chat and requires using only authorized accounts and saves. It contains no hardcoded credentials or unauthorized network operations. Access is scoped to the WorldOS MCP environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 02:45 PM
Security Audit — agent-trust-hub — worldos-simulation-play