skill-creator
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The instructions in
SKILL.mddirect the agent to execute local Python scripts, specificallyscripts/init_skill.pyandscripts/package_skill.py, to facilitate the automation of skill creation and distribution workflows. - [DYNAMIC_EXECUTION]: The
scripts/init_skill.pyscript dynamically generates a starter Python script (example.py) by populating a hardcoded internal template with user-provided parameters. This is a core functional requirement of the initialization tool. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of new agent instructions from user-provided data, creating a potential surface for indirect injection if generated skills are not carefully reviewed for embedded instructions.
- Ingestion points: User-supplied input for skill names, descriptions, and logic provided during the creation process in the
SKILL.mdtemplate. - Boundary markers: The tool does not automatically insert safety boundary markers or 'ignore embedded instructions' delimiters into the generated skill templates.
- Capability inventory: The skill utilizes file system write operations in
init_skill.pyand zip archival operations inpackage_skill.py. - Sanitization: Validation logic in
scripts/quick_validate.pyenforces hyphen-case naming conventions and prevents the use of HTML-style angle brackets in descriptions to mitigate basic injection or rendering issues.
Audit Metadata