skill-creator

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill uses yaml.safe_load() in scripts/quick_validate.py to process skill frontmatter, which prevents unsafe deserialization of arbitrary Python objects from YAML data.\n- [COMMAND_EXECUTION]: Automation scripts such as scripts/check_changed_files.py and scripts/validate_all.py use the subprocess module to execute git commands for repository maintenance. These calls use list-based arguments instead of shell strings, mitigating command injection risks.\n- [PRIVILEGE_ESCALATION]: The scripts/init_skill.py script applies executable permissions (chmod 0o755) to generated script templates. This is a functional requirement for its purpose as a scaffolding tool and is restricted to the specific files it creates.\n- [INDIRECT_PROMPT_INJECTION]: Because the skill generates new instructions based on user requests, there is a theoretical surface for indirect prompt injection. The skill mitigates this risk by providing the agent with instructions and references focused on behavior testing, routing validation, and manual review of all generated content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:21 PM
Security Audit — agent-trust-hub — skill-creator