skills-management

Warn

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Multiple scripts use subprocess.run to execute external commands and management tools.
  • scripts/optimize_skill.py and scripts/blind_comparator.py execute shell commands provided via arguments (e.g., --optimizer-cmd, --target-cmd) to interact with LLM providers.
  • scripts/trigger_test.py calls the claude CLI to judge triggering logic.
  • scripts/audit_skill_duplicates.py executes claude plugin list --json to inventory active plugins.
  • scripts/diff_skill_versions.py invokes git to compare skill versions across commits.
  • [DYNAMIC_EXECUTION]: The optimization loop in scripts/optimize_skill.py supports a custom verifier that executes a local script.
  • The verify_script function uses subprocess.run to execute a file path provided by the user, passing JSON-encoded task data to its stdin.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data that could influence agent behavior during optimization.
  • scripts/optimize_skill.py ingests task definitions from tasks.jsonl. This data is used to construct prompts and define assertions for LLM-based grading, creating an ingestion surface for untrusted instructions if the task set is sourced externally.
  • [EXTERNAL_DOWNLOADS]: The skill integrates with an external ecosystem for finding and adding skills.
  • The documentation and instructions guide the user to use the Skills CLI (npx skills), which fetches skill configurations and content from the https://skills.sh service and GitHub repositories (e.g., vercel-labs/add-skill).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 22, 2026, 02:48 AM
Security Audit — agent-trust-hub — skills-management