yy-check-skill-compliance
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill's behavior is consistent with an administrative utility. It performs directory listings and file reads within the project structure to verify adherence to standards.
- [COMMAND_EXECUTION]: The skill triggers 'yy-create-skill' upon user confirmation. This is an internal tool coordination pattern using vendor-owned resources and does not represent arbitrary command execution.
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it ingests untrusted markdown data from skill directories (Ingestion: 'SKILL.md' files; Boundaries: None; Capabilities: Internal skill triggering; Sanitization: None). Because the skill does not have network access or access to sensitive system files, the risk is negligible.
Audit Metadata