worldos-simulation-play
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read and interpret narrative outputs and player-visible state changes from the WorldOS platform. While these are external inputs, the skill limits the agent's actions to specific platform tools and emphasizes manual verification of results. Ingestion points include results from
play_owned_save_turnandget_owned_save_turns. Boundary markers are present in the form of instructions to separate "natural player interactions" from "engine operations or state paths." Capability inventory is restricted to the specificworldos-simulation-playMCP tools. Sanitization is not explicitly defined in the instructions, relying on platform-level controls. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill explicitly forbids requesting access tokens in chat and requires using only authorized accounts and saves. It contains no hardcoded credentials or unauthorized network operations. Access is scoped to the WorldOS MCP environment.
Audit Metadata