author-skill
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill integrates several local shell commands and scripts used for manifest generation, validation, and testing within the project environment. These include
npm run manifest,bash scripts/eval-lint.sh,npm run validate, andnode scripts/skill-behavior-eval.js. These are intended for local development workflows and project maintenance. - [DYNAMIC_EXECUTION]: A Python script snippet is included in
references/description-recipe.mdfor validating skill frontmatter. The script reads a file path provided as an argument and utilizesyaml.safe_loadto check specific metadata requirements such as theorigintag and the character length of the description field. - [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to read a local configuration file to adapt its interaction style.
- Ingestion points:
02-DOCS/wiki/harness/user-profile.md(referenced inSKILL.md). - Boundary markers: No explicit delimiters or warnings are specified for the content of this file.
- Capability inventory: The skill facilitates file authoring, manifest management via
npm, and execution of local verification scripts. - Sanitization: There are no mentioned filters or validation steps for the data retrieved from the user profile wiki page.
- [EXTERNAL_DOWNLOADS]: The skill references the command
npx @ericrisco/rsc, which utilizes the NPM package runner to execute a tool from the official registry. As the package is part of the@ericriscoorganization, which corresponds to the skill author, it is categorized as a vendor-owned resource used for catalog management.
Audit Metadata