skill-creator

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references a repository on the official Anthropics GitHub organization for benchmarking and automated testing infrastructure related to skill creation.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze conversation history and user-provided workflows to generate new instructions. This ingestion of external data constitutes a surface for indirect prompt injection, where malicious instructions embedded in the source material could potentially influence the agent's behavior or the content of the generated skill.
  • Ingestion points: User-provided workflow descriptions and previous conversation turns.
  • Boundary markers: The skill encourages clear structure but lacks explicit markers to isolate untrusted data during processing.
  • Capability inventory: The skill itself does not invoke dangerous tools but facilitates the creation of content that will be interpreted by the agent.
  • Sanitization: There are no explicit instructions to sanitize or filter user-provided input before using it to generate the skill body.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — skill-creator