skill-creator

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The scripts/init_skill.py script generates an executable Python file from a template string when creating new skill directories.\n- [PRIVILEGE_ESCALATION]: The init_skill.py script uses chmod(0o755) to grant executable permissions to the generated boilerplate script, which involves runtime permission modification.\n- [INDIRECT_PROMPT_INJECTION]: The skill functions as a generator for other skills, creating an attack surface where user-provided functionality descriptions are incorporated into generated instructions without explicit sanitization.\n
  • Ingestion points: User prompts defining new skill functionality and content for SKILL.md.\n
  • Boundary markers: No delimiters or isolation instructions are provided in the generation templates to handle untrusted user input.\n
  • Capability inventory: The toolset includes file system creation, file writing, and permission management capabilities.\n
  • Sanitization: The provided automation scripts do not include mechanisms for sanitizing or validating user input before it is written to the skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 06:52 PM