skills/boshu2/agentops/skill-builder/Gen Agent Trust Hub

skill-builder

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes standard system utilities such as go, rsync, perl, awk, and sed to manage skill packages and generate artifacts. These commands are used for legitimate build and transformation tasks.
  • [DYNAMIC_EXECUTION]: Through scripts/run-ao.sh, the skill compiles its core logic from a local Go source directory and runs the binary. This self-contained build process is typical for this type of meta-tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external skill content during audits and conversions. It provides protection against indirect injection by following a 'clean-room' approach that excludes third-party prompts and prose from generated output, and it uses directory containment checks to prevent unauthorized file operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 10:56 AM
Security Audit — agent-trust-hub — skill-builder