phaser-coder
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run
npx tsc --noEmitto validate TypeScript code. This is a common and legitimate development practice for ensuring code quality and catching errors before runtime. - [INDIRECT_PROMPT_INJECTION]: The skill processes user requests and reads existing project source files to generate new game code. This represents a standard attack surface where the agent ingests external data. However, no specific patterns for safety bypass or malicious instruction overrides were identified.
- [SAFE]: The skill uses a documentation lookup tool (Context7 MCP) for API verification, which is a safe retrieval operation. No patterns of data exfiltration, obfuscation, or unauthorized network access were found.
Audit Metadata