skill-creator

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Several utility scripts (scripts/run_eval.py, scripts/improve_description.py, eval-viewer/generate_review.py) utilize the subprocess module to execute system commands. This includes invoking the claude CLI for evaluation and the lsof utility for process management (port cleanup). These operations are essential to the skill's purpose and use list-based arguments to prevent shell injection vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The evaluation viewer component (eval-viewer/viewer.html) fetches the SheetJS library (xlsx.full.min.js) from cdn.sheetjs.com. This is a standard library used to render Excel outputs for user review within the HTML interface.
  • [PROMPT_INJECTION]: The skill implements an automated evaluation and improvement loop where the outputs of subagents are ingested and processed by subsequent subagents (graders and comparators). This architecture presents an indirect prompt injection surface. However, the risk is mitigated by the skill's workflow, which mandates human oversight via the eval-viewer to verify all automated outputs and optimizations.
  • Ingestion points: Subagent outputs stored in workspace directories (e.g., iteration-N/outputs/).
  • Boundary markers: Explicit instructions for human-in-the-loop review before adopting optimizations.
  • Capability inventory: Subprocess execution, file system management, and subagent spawning.
  • Sanitization: Relies on human review of feedback.json rather than automated input filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 12:46 PM
Security Audit — agent-trust-hub — skill-creator