skill-creator

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/init_skill.py script applies executable permissions (chmod 0o755) to generated example scripts. This is a standard functional requirement for a scaffolding tool to ensure that generated scripts are ready for use.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided strings to generate metadata in agents/openai.yaml. While metadata can theoretically be used for injection, the skill implements validation (character filtering and length limits) and uses safe string representation to ensure the generated YAML is well-formed.
  • Ingestion points: Command-line arguments in scripts/init_skill.py and scripts/generate_openai_yaml.py via the --interface flag.
  • Boundary markers: Generated metadata values are enclosed in single quotes within the resulting agents/openai.yaml file using Python's repr formatting.
  • Capability inventory: Local file and directory creation, file writing, and ZIP archive creation.
  • Sanitization: The scripts/quick_validate.py script enforces length constraints and prohibits specific characters (like angle brackets) in description fields.
  • [DYNAMIC_EXECUTION]: The skill generates boilerplate Python scripts from static templates defined within scripts/init_skill.py. This behavior is limited to project scaffolding and does not involve the execution of arbitrary or untrusted code at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:40 AM
Security Audit — agent-trust-hub — skill-creator