create-skill
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The instructions in
SKILL.mdandskill-template.mdinclude shell command examples (mkdir) and Python script executions. These are intended as developer templates rather than automated agent commands.\n- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it generates content from user requirements. \n - Ingestion points: User-provided domain examples and workflow queries are collected in
SKILL.md(Steps 1 and 2).\n - Boundary markers: The instructions do not define boundary markers for the resulting skill content.\n
- Capability inventory: The skill describes using file modification tools (
Write,Edit) to create the final skill files.\n - Sanitization: Content sanitization is not specified in the creation process.\n- [SAFE]: No obfuscation techniques, such as Base64 or hidden characters, were found. The skill does not hardcode credentials or communicate with unauthorized external servers. The included 'skill-report.json' was analyzed and contains no malicious indicators.
Audit Metadata