10-andruia-skill-smith

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions the agent to perform local file system operations as part of its deployment phase.
  • Evidence: FASE 3 in SKILL.md directs the creation of physical folders at D:\...\antigravity-awesome-skills\skills\ and writing README files within those folders.
  • Context: These actions are aligned with the primary purpose of the skill ('Skill-Smith') and are restricted to the local development environment.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface by processing user-supplied data to generate code.
  • Ingestion points: FASE 1 in SKILL.md solicits technical names, expert roles, and key outputs from the user.
  • Boundary markers: The skill does not explicitly define delimiters for this input, but includes strict structural guidelines ('Est�ndar de Diamante') to govern the output.
  • Capability inventory: The agent has the capability to write files to the local disk based on this input.
  • Sanitization: No explicit sanitization or filtering logic is described for the user-provided data before it is incorporated into the new skill templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 09:22 PM
Security Audit — agent-trust-hub — 10-andruia-skill-smith