skills/delorenj/skills/skill-creator/Gen Agent Trust Hub

skill-creator

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [PRIVILEGE_ESCALATION]: The initialization script (scripts/init_skill.py) applies executable permissions (chmod 0755) to generated example scripts. This is standard behavior for developer tools and is restricted to files created within the new skill directory.
  • [DYNAMIC_EXECUTION]: The skill generates new scripts and documentation from embedded templates. This behavior is the primary function of the tool and is controlled by user-provided parameters.
  • [INDIREC T_PRO M P T_INJE C T IO N]: The tool accepts user input for skill names and descriptions to populate YAML frontmatter. It implements hyphen-case normalization and proper YAML escaping to preven t malformed metadata or accidental instruction injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — skill-creator