create-paid-skill
Pass
Audited by Gen Agent Trust Hub on Mar 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its core functionality of processing external, potentially untrusted data to generate local files.
- Ingestion points: The skill is instructed to read and process external OpenAPI specifications (via URLs or local files) to automate the creation of
SKILL.mddocuments. - Boundary markers: The instructions do not specify the use of delimiters or specific guidance to prevent the agent from following instructions that might be embedded within the external OpenAPI documentation or endpoint descriptions.
- Capability inventory: The skill is granted powerful capabilities including
WriteandEditfor filesystem modification, andBashfor command execution, which increases the potential impact if a malicious instruction from an external source is executed by the agent. - Sanitization: While the skill provides high-level security advice for users, it lacks explicit logic for the agent to sanitize or escape data extracted from external specifications before using it in the file generation or validation process.
Audit Metadata