skill-architect

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to audit and process other skills, creating a potential surface for indirect prompt injection. If an agent audits a malicious skill, the instructions or code within that skill could manipulate the auditing agent.
  • Ingestion points: User-specified skill paths and file content during audit or improve actions.
  • Boundary markers: Absent; the skill does not explicitly define delimiters for untrusted skill content.
  • Capability inventory: The skill is granted Read, Write, Edit, and Bash tools, which are necessary for its architectural tasks but could be abused.
  • Sanitization: The provided scripts focus on syntax and structure validation rather than content sanitization for security.
  • [COMMAND_EXECUTION]: The skill requires the use of shell commands via the Bash tool to execute local utility scripts for skill lifecycle management.
  • [EXTERNAL_DOWNLOADS]: The skill documentation refers to standard dependencies from official package registries for extended functionality.
  • Fetches the Model Context Protocol SDK (@modelcontextprotocol/sdk) from the npm registry.
  • Recommends installing pillow and numpy from PyPI for image analysis tasks.
  • References official Anthropic repositories and SDKs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — skill-architect