skill-security-auditor
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains multiple strings commonly associated with prompt injection, such as 'Ignore previous instructions' and 'You are now...'. These occur in SKILL.md and references/threat-model.md as part of a list of patterns the tool is designed to detect in other skills. They are not intended to override the agent's behavior during the execution of this specific skill.
- [OBFUSCATION]: A base64-encoded string is present in references/threat-model.md. This string decodes to a malicious Python command involving a reverse shell. However, this is explicitly labeled as a 'Known Attack Pattern' for educational purposes and is not executed by the skill's scripts.
- [COMMAND_EXECUTION]: The script scripts/skill_security_auditor.py uses subprocess.run() to execute git clone. This is the intended functionality of the tool to allow auditing of remote skill repositories. It uses safe practices, such as passing arguments as a list and avoiding shell=True for this operation.
- [INDIRECT_PROMPT_INJECTION]: The tool ingests untrusted data by reading the contents of the skill directory it is auditing. However, this data is processed as static text for regex matching and reporting. It is not executed or fed back into an LLM prompt in a way that could lead to instruction hijacking.
Audit Metadata