team-builder
Warn
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill implements a 'Skill Creation Workflow' that generates new SKILL.md instruction files at runtime and saves them to the .claude/skills/ directory. This behavior allows the agent to dynamically expand the platform's capabilities and instruction sets, effectively generating new executable-like modules based on its own analysis or user input.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external skill files located in .claude/skills/ during its gap analysis phase.
- Ingestion points: Reads content from .claude/skills/*/SKILL.md using Glob and Read tools.
- Boundary markers: The instructions do not define delimiters or warnings to ignore embedded instructions within the files it reads.
- Capability inventory: The skill has access to Bash, Write, Edit, Grep, and Glob tools across its operations.
- Sanitization: There is no documented logic for sanitizing or validating the content of existing skills before they are processed to determine the needs for new skill creation.
- [COMMAND_EXECUTION]: The skill is explicitly granted Bash tool access and its workflow includes shell-based discovery patterns, such as searching for existing files. When combined with the ability to write new instructions, this access increases the potential impact if the skill's logic is subverted.
Audit Metadata