skill-creator
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references a repository on the official Anthropics GitHub organization for benchmarking and automated testing infrastructure related to skill creation.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze conversation history and user-provided workflows to generate new instructions. This ingestion of external data constitutes a surface for indirect prompt injection, where malicious instructions embedded in the source material could potentially influence the agent's behavior or the content of the generated skill.
- Ingestion points: User-provided workflow descriptions and previous conversation turns.
- Boundary markers: The skill encourages clear structure but lacks explicit markers to isolate untrusted data during processing.
- Capability inventory: The skill itself does not invoke dangerous tools but facilitates the creation of content that will be interpreted by the agent.
- Sanitization: There are no explicit instructions to sanitize or filter user-provided input before using it to generate the skill body.
Audit Metadata