article-prompts-to-skills

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform local shell operations for repository state management and validation.\n
  • Evidence: Usage of git status and git diff to verify the state of the workspace before and after modifications (Steps 1 and 8).\n
  • Evidence: Execution of local repository scripts such as quick_validate.py and the skill-creator initializer (Steps 4 and 7).\n- [PROMPT_INJECTION]: The skill is designed to ingest and transform untrusted external data (articles and tutorials), presenting a surface for indirect prompt injection.\n
  • Ingestion points: The skill reads source articles and tutorial content to extract logic and prompts (Step 1).\n
  • Boundary markers: The instructions mandate the removal of branding, marketing copy, and source-specific packaging to isolate core logic (Step 3).\n
  • Capability inventory: The skill has the authority to write new files to the agent-skills/ directory, execute local validation scripts, and perform Git commits.\n
  • Sanitization: The workflow includes a mandatory security scan (Step 7.8) to check all changed files for secrets, tokens, and private client data before committing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:32 AM
Security Audit — agent-trust-hub — article-prompts-to-skills