BeCreative
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses local shell commands for operational tasks: it employs
curlto send status notifications to a local server (http://localhost:31337/notify) andechoto append JSON-formatted execution logs to~/.claude/LIFEOS/MEMORY/SKILLS/execution.jsonl. - [COMMAND_EXECUTION]: The
TechnicalCreativityGemini3workflow utilizes thellmCLI tool to offload specialized technical reasoning tasks to external models. - [PROMPT_INJECTION]: The
SyntheticDataExpansionworkflow presents a surface for indirect prompt injection by ingesting and processing user-provided seed corpora. - Ingestion points: User-supplied 'Seed corpus' in the
SyntheticDataExpansion.mdworkflow. - Boundary markers: The workflow uses clear text headers (
SCHEMA:,SEED CORPUS:) to delineate instructions from untrusted input data. - Capability inventory: The skill has the ability to write to the local filesystem (
echo) and execute specific CLI utilities (llm,curl). - Sanitization: Risk is mitigated through mandatory JSON schema validation and semantic deduplication of the generated output.
Audit Metadata