skill-creator
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The
scripts/init_skill.pyscript generates an executable Python file from a template string when creating new skill directories.\n- [PRIVILEGE_ESCALATION]: Theinit_skill.pyscript useschmod(0o755)to grant executable permissions to the generated boilerplate script, which involves runtime permission modification.\n- [INDIRECT_PROMPT_INJECTION]: The skill functions as a generator for other skills, creating an attack surface where user-provided functionality descriptions are incorporated into generated instructions without explicit sanitization.\n - Ingestion points: User prompts defining new skill functionality and content for
SKILL.md.\n - Boundary markers: No delimiters or isolation instructions are provided in the generation templates to handle untrusted user input.\n
- Capability inventory: The toolset includes file system creation, file writing, and permission management capabilities.\n
- Sanitization: The provided automation scripts do not include mechanisms for sanitizing or validating user input before it is written to the skill files.
Audit Metadata