skill-maker
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell commands like
mkdir,git, andghto manage the skill development lifecycle, including directory creation and GitHub repository initialization. It also employs dynamic context injection using the!catpattern to load shared protocol files (e.g.,ux-protocol.md,input-validation.md) from the local environment into the agent's active context at load time. - [PROMPT_INJECTION]: As a tool designed to generate agent instructions from user-provided workflow descriptions, the skill presents an inherent surface for indirect prompt injection. This risk is mitigated by the skill's structured process, which includes explicit testing, evaluation, and iteration phases to ensure generated instructions are safe and effective.
Audit Metadata