skill-creator

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The instructions in SKILL.md direct the agent to execute local Python scripts, specifically scripts/init_skill.py and scripts/package_skill.py, to facilitate the automation of skill creation and distribution workflows.
  • [DYNAMIC_EXECUTION]: The scripts/init_skill.py script dynamically generates a starter Python script (example.py) by populating a hardcoded internal template with user-provided parameters. This is a core functional requirement of the initialization tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of new agent instructions from user-provided data, creating a potential surface for indirect injection if generated skills are not carefully reviewed for embedded instructions.
  • Ingestion points: User-supplied input for skill names, descriptions, and logic provided during the creation process in the SKILL.md template.
  • Boundary markers: The tool does not automatically insert safety boundary markers or 'ignore embedded instructions' delimiters into the generated skill templates.
  • Capability inventory: The skill utilizes file system write operations in init_skill.py and zip archival operations in package_skill.py.
  • Sanitization: Validation logic in scripts/quick_validate.py enforces hyphen-case naming conventions and prevents the use of HTML-style angle brackets in descriptions to mitigate basic injection or rendering issues.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:08 PM
Security Audit — agent-trust-hub — skill-creator