creating-skills
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
subprocessmodule in several utility scripts (scripts/run_eval.py,scripts/improve_description.py, andeval-viewer/generate_review.py) to invoke the platform's native CLI tool (claude). These calls are used to test skill triggering thresholds, generate description improvements, and manage local processes for the results viewer. This is intended functionality for a development-focused skill. - [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection because it ingests untrusted user-defined test queries (stored in
evals/evals.jsonor provided viascripts/run_loop.py) and interpolates them into commands executed by subagents. While necessary for benchmarking, malicious instructions in these test prompts could theoretically influence the execution of the subagents during the evaluation phase. - [EXTERNAL_DOWNLOADS]: The results viewer (
eval-viewer/viewer.html) loads the SheetJS library from a well-known service (cdn.sheetjs.com) to enable the rendering of spreadsheet files within the browser. This is a standard implementation for local data visualization and targets an established third-party provider.
Audit Metadata