skill-validation
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill's primary function is to perform quality assurance on other skills using local scripts (
validation/validate-skill.shandlinting/lint-skill.sh). These operations are consistent with the skill's stated purpose and do not involve network requests, sensitive data access, or privilege escalation. - [PROMPT_INJECTION]: The skill exhibits a potential surface for indirect prompt injection as it is designed to ingest and analyze untrusted skill definitions.
- Ingestion points: The
skills/directory containing theSKILL.mdand associated reference files of the project being validated. - Boundary markers: Absent; the agent reads and evaluates the content directly against the provided rubric without explicit delimiters.
- Capability inventory: Execution of local shell scripts for linting and structural checks.
- Sanitization: Absent; the analysis relies on the agent's ability to qualitatively score the content.
Audit Metadata