tune-enemy-ai
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a process for gathering observable inputs from external sources (e.g., distance, target state, timers) and performing browser-based encounter testing. This creates a data ingestion surface where external, potentially untrusted game state content is incorporated into the agent's context.
- Ingestion points: SKILL.md (gathering observable inputs, running browser encounters)
- Boundary markers: Absent; the instructions do not specify using delimiters or explicit warnings to ignore instructions embedded in game data.
- Capability inventory: Interaction with browser environments and state machines (implied).
- Sanitization: Absent; no validation or filtering of external inputs is mentioned.
Audit Metadata