skill-creator

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a legitimate developer toolkit for scaffolding and distributing AI agent skills. Its scripts and documentation are consistent with its stated purpose.
  • [COMMAND_EXECUTION]: Includes Python scripts (init_skill.py, package_skill.py, quick_validate.py) for file system management, such as directory creation, file writing, and archive generation. These are standard automation tasks for project scaffolding and do not involve suspicious command execution or shell injection.
  • [DATA_EXFILTRATION]: No network-enabled tools or instructions for external data transmission were found. The scripts operate exclusively on the local file system within the scope of the provided paths.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials, API keys, or access patterns to sensitive environment variables or configuration files were detected.
  • [PROMPT_INJECTION]: The instructions in SKILL.md and the reference files focus on structural guidance and do not contain patterns intended to bypass safety filters or override agent constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:18 PM
Security Audit — agent-trust-hub — skill-creator