skill-grader
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves ingesting untrusted data by reading full directory contents (SKILL.md, scripts, and documentation) of other agent skills. This creates an attack surface where a maliciously crafted target skill could contain instructions designed to manipulate the grader's output or subvert the evaluation process.\n
- Ingestion points: The 'Grading Process' section in SKILL.md explicitly instructs the agent to read the entire skill folder, including SKILL.md and all referenced files.\n
- Boundary markers: There are no instructions provided in SKILL.md to treat the ingested data as untrusted or to use specific delimiters to prevent the agent from following instructions embedded within the target files.\n
- Capability inventory: The skill is restricted to Read, Grep, and Glob tools (as defined in SKILL.md frontmatter), which limits the potential impact of an injection to the current session's output rather than enabling file system writes or network exfiltration.\n
- Sanitization: The workflow in SKILL.md lacks a validation or sanitization step for the external content before it is processed by the agent's reasoning engine.
Audit Metadata