skill-tester
Warn
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONMETADATA_POISONING
Full Analysis
- [REMOTE_CODE_EXECUTION]: The
scripts/script_tester.pycomponent identifies and executes Python files found in the target skill directory provided by the user. It usessubprocess.runto invoke the Python interpreter on these external scripts during various testing phases, including syntax validation, help message verification, and sample data processing. - [COMMAND_EXECUTION]: Multiple functions in
scripts/script_tester.py(such as_test_script_execution,_test_help_functionality, and_test_sample_data_processing) execute shell-level commands by spawning subprocesses. These commands run with the permissions of the current user and execute code provided in the target directory without adequate isolation. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process a wide variety of untrusted files from external skill repositories, making it vulnerable to indirect prompt injection.
- Ingestion points: Files including
SKILL.md,README.md, and assets are read usingPath.read_text()inscripts/skill_validator.py,scripts/script_tester.py, andscripts/quality_scorer.py. - Boundary markers: There are no explicit boundary markers or instructions to the agent to ignore potentially malicious embedded commands within the ingested content.
- Capability inventory: The skill includes the capability to execute code via
subprocess.runand read arbitrary files accessible to the agent. - Sanitization: Content is parsed for structural and syntax validation using
ast.parse, but no sanitization or environment sandboxing is applied when the scripts are executed. - [DYNAMIC_EXECUTION]: The skill relies on locating and running executable content at runtime based on the file structure of a provided path. It dynamically builds command strings to test scripts discovered in the target
scripts/folder. - [METADATA_POISONING]: There is a contradiction in the skill's ownership metadata; the
SKILL.mdfile identifies the author as the "Claude Skills Engineering Team," whereas the execution context attributes the skill to the user "alvindean."
Audit Metadata