yy-check-skill-compliance

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill's behavior is consistent with an administrative utility. It performs directory listings and file reads within the project structure to verify adherence to standards.
  • [COMMAND_EXECUTION]: The skill triggers 'yy-create-skill' upon user confirmation. This is an internal tool coordination pattern using vendor-owned resources and does not represent arbitrary command execution.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it ingests untrusted markdown data from skill directories (Ingestion: 'SKILL.md' files; Boundaries: None; Capabilities: Internal skill triggering; Sanitization: None). Because the skill does not have network access or access to sensitive system files, the risk is negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 02:56 AM
Security Audit — agent-trust-hub — yy-check-skill-compliance