skill-creator
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes Python utilities (
scripts/init_skill.pyandscripts/package_skill.py) that perform local file system operations. These scripts automate the creation of project directories, template generation, and archiving of skill packages into ZIP format as part of the development lifecycle. - [PRIVILEGE_ESCALATION]: The
scripts/init_skill.pyscript programmatically modifies file permissions usingchmod(0o755)for newly created template scripts. While this is expected behavior for a project initializer to ensure scripts are runnable, it constitutes automated privilege modification on dynamically created content. - [SAFE]: No evidence of prompt injection, data exfiltration, or malicious obfuscation was detected. The automated scanner alert regarding
SKILL.mdwas evaluated and determined to be a likely heuristic false positive triggered by the instructional nature of the content.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata