agent-md-creator
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the analysis and processing of untrusted repository data, which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: The
SKILL.mdfile instructs the agent to inspect theREADME, command definitions, CI configurations, and repository code to establish facts for generating instructions. - Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat external repository content as data rather than instructions, nor are there warnings to ignore embedded commands within those files.
- Capability inventory: The skill workflow requires the agent to read repository files and write new
AGENTS.mdfiles, providing a functional path for injection to manifest in repository documentation. - Sanitization: The skill does not define any validation, filtering, or escaping protocols for the content it reads before it is interpolated into the generated instruction files.
Audit Metadata