article-prompts-to-skills
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform local shell operations for repository state management and validation.\n
- Evidence: Usage of
git statusandgit diffto verify the state of the workspace before and after modifications (Steps 1 and 8).\n - Evidence: Execution of local repository scripts such as
quick_validate.pyand theskill-creatorinitializer (Steps 4 and 7).\n- [PROMPT_INJECTION]: The skill is designed to ingest and transform untrusted external data (articles and tutorials), presenting a surface for indirect prompt injection.\n - Ingestion points: The skill reads source articles and tutorial content to extract logic and prompts (Step 1).\n
- Boundary markers: The instructions mandate the removal of branding, marketing copy, and source-specific packaging to isolate core logic (Step 3).\n
- Capability inventory: The skill has the authority to write new files to the
agent-skills/directory, execute local validation scripts, and perform Git commits.\n - Sanitization: The workflow includes a mandatory security scan (Step 7.8) to check all changed files for secrets, tokens, and private client data before committing.
Audit Metadata