skill-creator

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized access attempts were detected in the skill instructions or examples.
  • [PROMPT_INJECTION]: The skill involves generating AI instructions based on user intent and existing project files, creating a surface for indirect prompt injection.
  • Ingestion points: User requirements captured via dialogue and existing SKILL.md files in the repository.
  • Boundary markers: The skill suggests standard markdown headers but does not require specific injection-prevention delimiters.
  • Capability inventory: The agent is instructed to create directories and write to SKILL.md and config.json files.
  • Sanitization: No explicit input sanitization or validation is recommended for the generated content, as it is intended as a development tool.
  • [COMMAND_EXECUTION]: The documentation and examples include references to shell commands such as npm, aws, and git. These are provided as educational examples for users to incorporate into their own skills and are not executed by the skill-creator skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 02:39 PM
Security Audit — agent-trust-hub — skill-creator