write-a-skill
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides instructional content and templates for skill development. It does not perform network operations, access sensitive system files, or include obfuscated code.
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it processes user requirements to generate SKILL.md files. This is mitigated by instructions to define clear operational boundaries and the requirement for a human-in-the-loop review phase. • Ingestion points: user requirements gathered in Phase 1. • Boundary markers: instruction to define 'what this skill does NOT do' in Phase 1 and validation during Phase 3. • Capability inventory: Read, Grep, Glob, Bash, Write, and Edit tools for file manipulation. • Sanitization: manual validation by the user.
Audit Metadata