hytopia-world
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE] (SAFE): The skill is purely instructional, containing TypeScript code snippets for the HYTOPIA SDK. No malicious patterns, obfuscation, or unauthorized data access were found.
- [DATA_EXPOSURE_AND_EXFILTRATION] (SAFE): All external links point to official developer documentation and tools at dev.hytopia.com and build.hytopia.com.
- [INDIRECT_PROMPT_INJECTION] (LOW): The skill demonstrates loading world data from a JSON file (world.json). While this is a data ingestion surface, it is a standard practice for game engines, and no exploitable capabilities (like command execution) are present in the provided context.
Audit Metadata