skill-creator
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The automated scanner's detection of
SKILL.mdas malicious is a false positive. A manual audit of the file confirms it contains only instructional markdown and configuration examples for agent development, with no evidence of malicious code, hidden payloads, or harmful scripts. - [COMMAND_EXECUTION]: The skill provides Python scripts (
scripts/init_skill.py,scripts/package_skill.py) that automate local file system tasks such as directory creation, template generation, and ZIP archiving. These operations are performed using standard libraries and are consistent with the skill's purpose as a developer utility. - [DYNAMIC_EXECUTION]: The
quick_validate.pyscript uses theyaml.safe_loadfunction to process YAML metadata. This is a secure implementation that prevents arbitrary code execution during the parsing of configuration files. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided task descriptions to generate instructions for other AI agents. While this capability presents a surface for indirect prompt injection, the skill does not possess sensitive data access or network capabilities that would allow for exploitation or exfiltration, resulting in a safe environment.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata