skill-test

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the !command syntax to execute a shell command during the skill loading phase: !source "${CLAUDE_PROJECT_DIR:-.}/.claude/hooks/yaml-helper.sh" 2>/dev/null && resolve_config --keys automation. This command is used to resolve environment-specific configuration values and does not involve exfiltration of sensitive data or unauthorized access to system-level files.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and evaluate the content of other instruction files (skills and specs) located within the project's directory structure. This introduces an attack surface where a malicious skill being tested could contain instructions designed to influence the agent's logic during the evaluation process.
  • Ingestion points: Phase 2A, 2B, and 2D read content from project-level skill files and rubric definitions.
  • Boundary markers: The skill does not explicitly define delimiters or "ignore instructions" markers when interpolating the content of skills into the evaluation prompts.
  • Capability inventory: The skill has Write permissions and is authorized to modify catalog.yaml and create new result files in the framework's results directory.
  • Sanitization: There is no evidence of sanitization or escaping of the skill content before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill uses standard file system tools (Read, Glob, Grep) to iterate through project directories and inspect file contents. These operations are scoped to the project environment and are consistent with the skill's stated purpose of auditing and linting.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 09:12 AM
Security Audit — agent-trust-hub — skill-test