skill-creator

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts user input during its interview phases and interpolates this content directly into the generated SKILL.md and reference files. This creates a surface for indirect prompt injection where a user could provide malicious instructions as part of their answers. * Ingestion points: User responses to Phase 1 and Phase 3 questions in SKILL.md. * Boundary markers: The skill enforces a structured 7-section anatomy using a template (assets/skill-template.md). * Capability inventory: File system write access for skill folder generation. * Sanitization: The process relies on a manual user approval step and a quality checklist (references/quality-checklist.md) rather than automated sanitization.
  • [COMMAND_EXECUTION]: The skill requires the agent to execute file system operations including creating directories and writing files. While this is the intended purpose of the skill, it involves tool execution that could be misused if the agent attempts to write files outside the intended skill directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 09:19 AM
Security Audit — agent-trust-hub — skill-creator