voxel-art

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOWPROMPT_INJECTION
Full Analysis
  • PROMPT_INJECTION (LOW): The skill instructions mandate the use of external reference files (references/patterns.md, references/sharp_edges.md, references/validations.md) as the source of truth. This creates an indirect prompt injection vector where an attacker who can modify these files could influence the agent output.
  • Ingestion points: SKILL.md (Reference System Usage section) references external files for creation, diagnosis, and review rules.
  • Boundary markers: Absent; the agent is told to ground responses in these files without specific delimiters or warnings to ignore embedded commands.
  • Capability inventory: None detected. The skill is limited to providing art advice and does not possess file-write, network-access, or command-execution capabilities.
  • Sanitization: Absent.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 12:52 AM