10-andruia-skill-smith
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions the agent to perform local file system operations as part of its deployment phase.
- Evidence: FASE 3 in
SKILL.mddirects the creation of physical folders atD:\...\antigravity-awesome-skills\skills\and writing README files within those folders. - Context: These actions are aligned with the primary purpose of the skill ('Skill-Smith') and are restricted to the local development environment.
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface by processing user-supplied data to generate code.
- Ingestion points: FASE 1 in
SKILL.mdsolicits technical names, expert roles, and key outputs from the user. - Boundary markers: The skill does not explicitly define delimiters for this input, but includes strict structural guidelines ('Est�ndar de Diamante') to govern the output.
- Capability inventory: The agent has the capability to write files to the local disk based on this input.
- Sanitization: No explicit sanitization or filtering logic is described for the user-provided data before it is incorporated into the new skill templates.
Audit Metadata