skill-scout

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to search for and ingest content from external SKILL.md files found on GitHub or the web, which could contain adversarial instructions intended to influence the agent's behavior.
  • Ingestion points: The agent is instructed to fetch and read SKILL.md files from remote GitHub repositories and web search results (Step 3 and Step 4).
  • Boundary markers: The instructions do not define technical delimiters for the external content but do provide a conceptual boundary by directing the agent to vet the content before adoption.
  • Capability inventory: The skill utilizes find, grep, and gh search tools. The overall workflow is intended to lead to the creation or modification of skills, which typically involves file system writes and command execution.
  • Sanitization: Step 4 ("Vet External Matches") and the "Anti-Patterns" section provide explicit instructions for the agent to manually review code for unexpected shell commands, network calls, and credential handling, acting as a procedural safeguard.
  • [COMMAND_EXECUTION]: The skill utilizes local shell commands and CLI tools to perform its primary search functions.
  • Evidence: The skill uses find and grep to scan the ~/.claude/skills and ~/.claude/plugins/marketplaces directories for existing configuration files.
  • Evidence: The skill uses the GitHub CLI (gh) to search for remote repositories and code matching the user's intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — skill-scout