skill-creator
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/init_skill.pyscript applies executable permissions (chmod 0o755) to generated example scripts. This is a standard functional requirement for a scaffolding tool to ensure that generated scripts are ready for use. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided strings to generate metadata in
agents/openai.yaml. While metadata can theoretically be used for injection, the skill implements validation (character filtering and length limits) and uses safe string representation to ensure the generated YAML is well-formed. - Ingestion points: Command-line arguments in
scripts/init_skill.pyandscripts/generate_openai_yaml.pyvia the--interfaceflag. - Boundary markers: Generated metadata values are enclosed in single quotes within the resulting
agents/openai.yamlfile using Python'sreprformatting. - Capability inventory: Local file and directory creation, file writing, and ZIP archive creation.
- Sanitization: The
scripts/quick_validate.pyscript enforces length constraints and prohibits specific characters (like angle brackets) in description fields. - [DYNAMIC_EXECUTION]: The skill generates boilerplate Python scripts from static templates defined within
scripts/init_skill.py. This behavior is limited to project scaffolding and does not involve the execution of arbitrary or untrusted code at runtime.
Audit Metadata