skill-coach

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes scripts such as scripts/validate_skill.py and scripts/check_self_contained.py that read and analyze the content of other agent skills from a directory path provided by the user. This represents a surface where a malicious skill being audited could attempt to influence the agent's behavior via the resulting analysis output. The scripts use yaml.safe_load for parsing metadata and regular expressions for content evaluation, which are standard and safe practices for processing such data.
  • [COMMAND_EXECUTION]: The skill frontmatter specifies allowed-tools: Bash(python:*), which allows the agent to execute the included Python-based validation and testing tools. This permission is scoped specifically to Python commands and is necessary for the skill's primary function of local skill auditing.
  • [EXTERNAL_DOWNLOADS]: The documentation and examples within the skill (e.g., in examples/good/clip-aware-embeddings/SKILL_.md) reference the installation of common machine learning and image processing libraries from the official PyPI registry, such as transformers, torch, and pillow. These references target well-known services and trusted packages, representing standard development practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:08 PM
Security Audit — agent-trust-hub — skill-coach