skill-scout
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to search for and ingest content from external
SKILL.mdfiles found on GitHub or the web, which could contain adversarial instructions intended to influence the agent's behavior. - Ingestion points: The agent is instructed to fetch and read
SKILL.mdfiles from remote GitHub repositories and web search results (Step 3 and Step 4). - Boundary markers: The instructions do not define technical delimiters for the external content but do provide a conceptual boundary by directing the agent to vet the content before adoption.
- Capability inventory: The skill utilizes
find,grep, andgh searchtools. The overall workflow is intended to lead to the creation or modification of skills, which typically involves file system writes and command execution. - Sanitization: Step 4 ("Vet External Matches") and the "Anti-Patterns" section provide explicit instructions for the agent to manually review code for unexpected shell commands, network calls, and credential handling, acting as a procedural safeguard.
- [COMMAND_EXECUTION]: The skill utilizes local shell commands and CLI tools to perform its primary search functions.
- Evidence: The skill uses
findandgrepto scan the~/.claude/skillsand~/.claude/plugins/marketplacesdirectories for existing configuration files. - Evidence: The skill uses the GitHub CLI (
gh) to search for remote repositories and code matching the user's intent.
Audit Metadata