skill-generator

Warn

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The generated autonomous orchestrator logic in 'phases/03-phase-generation.md' includes an 'eval()' call within the 'checkPreconditions' function. This pattern allows for the dynamic execution of strings derived from state variables and configuration fields, which could be exploited to run arbitrary JavaScript if the skill's state is manipulated.
  • [COMMAND_EXECUTION]: The 'templates/llm-action.md' file defines preset prompt templates that incorporate shell command substitution patterns (e.g., '$(cat ...)' for loading protocols). While the skill includes an 'escapePrompt' utility to mitigate injection, the inclusion of executable shell patterns in prompt templates represents a risky design choice that could be bypassed or abused in the generated execution environment.
  • [INDIRECT_PROMPT_INJECTION]: As a meta-skill generator, this tool produces artifacts designed to ingest and process untrusted project data (e.g., source code scanning and analysis steps in 'templates/code-analysis-action.md'). Although the templates provide boundary markers like '[TASK]' and '[CONTEXT]', the resulting skills possess broad capabilities (Bash, Agent, Write) paired with ingestion of untrusted data, qualifying as a surface for indirect prompt injection.
  • Ingestion points: Generated skills read project source code via 'Glob' and 'Read' operations defined in 'templates/code-analysis-action.md' and 'templates/sequential-phase.md'.
  • Boundary markers: The prompt templates in 'templates/llm-action.md' and 'templates/sequential-phase.md' utilize headers like '[PHASE]', '[TASK]', and '[CONTEXT]' to delimit instructions from data.
  • Capability inventory: The generated skills are configured with capabilities including 'Bash', 'Agent', 'Read', and 'Write' across their orchestrators and action files.
  • Sanitization: The 'templates/llm-action.md' template includes an 'escapePrompt' function intended to sanitize prompts before they are passed to the 'ccw cli' shell command.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 24, 2026, 05:45 AM