skills-management
Warn
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: Multiple scripts use
subprocess.runto execute external commands and management tools. scripts/optimize_skill.pyandscripts/blind_comparator.pyexecute shell commands provided via arguments (e.g.,--optimizer-cmd,--target-cmd) to interact with LLM providers.scripts/trigger_test.pycalls theclaudeCLI to judge triggering logic.scripts/audit_skill_duplicates.pyexecutesclaude plugin list --jsonto inventory active plugins.scripts/diff_skill_versions.pyinvokesgitto compare skill versions across commits.- [DYNAMIC_EXECUTION]: The optimization loop in
scripts/optimize_skill.pysupports a custom verifier that executes a local script. - The
verify_scriptfunction usessubprocess.runto execute a file path provided by the user, passing JSON-encoded task data to its stdin. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data that could influence agent behavior during optimization.
scripts/optimize_skill.pyingests task definitions fromtasks.jsonl. This data is used to construct prompts and define assertions for LLM-based grading, creating an ingestion surface for untrusted instructions if the task set is sourced externally.- [EXTERNAL_DOWNLOADS]: The skill integrates with an external ecosystem for finding and adding skills.
- The documentation and instructions guide the user to use the Skills CLI (
npx skills), which fetches skill configurations and content from thehttps://skills.shservice and GitHub repositories (e.g.,vercel-labs/add-skill).
Audit Metadata