phaser-coder

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run npx tsc --noEmit to validate TypeScript code. This is a common and legitimate development practice for ensuring code quality and catching errors before runtime.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user requests and reads existing project source files to generate new game code. This represents a standard attack surface where the agent ingests external data. However, no specific patterns for safety bypass or malicious instruction overrides were identified.
  • [SAFE]: The skill uses a documentation lookup tool (Context7 MCP) for API verification, which is a safe retrieval operation. No patterns of data exfiltration, obfuscation, or unauthorized network access were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 08:07 PM
Security Audit — agent-trust-hub — phaser-coder