skillify
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/skillify_check.pyexecutes several system-level commands viasubprocess.run, includinggit rev-parsefor repository metadata,bash -nandnode --checkfor syntax validation, andnpxfor skill registry checks. - [DYNAMIC_EXECUTION]: The
scripts/skillify_check.pyscript includes an optional--run-testsflag that usessubprocess.runto invokepyteston code within thetests/directory of a target skill. - [EXTERNAL_DOWNLOADS]: The
scripts/skillify_check.pyscript performs network requests by executingnpx skills add --listagainst repository targets. - [INDIRECT_PROMPT_INJECTION]: The skill distills potentially untrusted session data into code and tests.
- Ingestion points: Chat history and session logs via the
look-backlens. - Boundary markers: No specific delimiters are implemented in the automated script to isolate session data.
- Capability inventory: Includes file writing, syntax validation, and test execution.
- Sanitization: The tool does not explicitly sanitize the ingested session data before distillation.
Audit Metadata