ai-game-developer

Pass

Audited by Gen Agent Trust Hub on Mar 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its processing of external specification data which influences agent outputs. 1. Ingestion points: Data is ingested from ai_game_runtime_spec.json using the validate_ai_game_runtime.py script. 2. Boundary markers: The skill lacks specific delimiters or instructions to ignore instructions found within the ingested JSON data. 3. Capability inventory: The skill generates a Patch Plan for modifying game runtime and configuration files based on the ingested data. 4. Sanitization: The validation script enforces schema and type constraints but does not sanitize string values for potential natural language instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 10, 2026, 03:28 AM