skills/broomva/skills/skillify/Gen Agent Trust Hub

skillify

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/skillify_check.py executes several system-level commands via subprocess.run, including git rev-parse for repository metadata, bash -n and node --check for syntax validation, and npx for skill registry checks.
  • [DYNAMIC_EXECUTION]: The scripts/skillify_check.py script includes an optional --run-tests flag that uses subprocess.run to invoke pytest on code within the tests/ directory of a target skill.
  • [EXTERNAL_DOWNLOADS]: The scripts/skillify_check.py script performs network requests by executing npx skills add --list against repository targets.
  • [INDIRECT_PROMPT_INJECTION]: The skill distills potentially untrusted session data into code and tests.
  • Ingestion points: Chat history and session logs via the look-back lens.
  • Boundary markers: No specific delimiters are implemented in the automated script to isolate session data.
  • Capability inventory: Includes file writing, syntax validation, and test execution.
  • Sanitization: The tool does not explicitly sanitize the ingested session data before distillation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:35 PM
Security Audit — agent-trust-hub — skillify