agent-md-creator

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the analysis and processing of untrusted repository data, which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The SKILL.md file instructs the agent to inspect the README, command definitions, CI configurations, and repository code to establish facts for generating instructions.
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat external repository content as data rather than instructions, nor are there warnings to ignore embedded commands within those files.
  • Capability inventory: The skill workflow requires the agent to read repository files and write new AGENTS.md files, providing a functional path for injection to manifest in repository documentation.
  • Sanitization: The skill does not define any validation, filtering, or escaping protocols for the content it reads before it is interpolated into the generated instruction files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:20 PM
Security Audit — agent-trust-hub — agent-md-creator