skill-tester
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [COMMAND_EXECUTION]: The
script_tester.pyutility usessubprocess.runto execute Python scripts found in the target skill's directory. This is used for runtime validation of help commands and sample data processing. The implementation follows best practices by using argument lists instead of shell strings and includes execution timeouts to prevent resource exhaustion. - [DYNAMIC_EXECUTION]: The skill implements a framework that dynamically discovers and executes Python code from a user-provided directory path. It mitigates potential risks by performing a static analysis pass using the
astmodule to verify syntax and ensure that the code only imports standard library modules before execution. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes content from external skill packages.
- Ingestion points: Reads files such as
SKILL.md(containing YAML frontmatter),README.md, and Python scripts from a target directory. - Boundary markers: The tool does not use specific delimiters to isolate untrusted content from its instructions, though it does treat the content as data for validation.
- Capability inventory: The skill has the ability to execute code via
subprocess.runand perform file system operations. - Sanitization: It employs
yaml.safe_loadfor frontmatter parsing andast.parsefor script validation, providing significant protection against malicious content during the analysis phase. - [METADATA_POISONING]: The documentation and script headers claim the skill has 'Zero External Dependencies' and uses the 'Python standard library only'. However,
skill_validator.pyandquality_scorer.pyboth depend on the externalPyYAMLlibrary for parsing frontmatter. WhilePyYAMLis a common and reputable package, the claim is technically inaccurate.
Audit Metadata