skills/base/skills/skill-creator/Gen Agent Trust Hub

skill-creator

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes Python utilities (scripts/init_skill.py and scripts/package_skill.py) that perform local file system operations. These scripts automate the creation of project directories, template generation, and archiving of skill packages into ZIP format as part of the development lifecycle.
  • [PRIVILEGE_ESCALATION]: The scripts/init_skill.py script programmatically modifies file permissions using chmod(0o755) for newly created template scripts. While this is expected behavior for a project initializer to ensure scripts are runnable, it constitutes automated privilege modification on dynamically created content.
  • [SAFE]: No evidence of prompt injection, data exfiltration, or malicious obfuscation was detected. The automated scanner alert regarding SKILL.md was evaluated and determined to be a likely heuristic false positive triggered by the instructional nature of the content.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 16, 2026, 08:48 PM
Security Audit — agent-trust-hub — skill-creator