antigravity-skill-orchestrator

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download a master catalog from a remote GitHub repository at 'https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/CATALOG.md'. This source is an unverified community account rather than a known technology service or trusted organization.
  • [PROMPT_INJECTION]: The orchestrator possesses an indirect prompt injection surface by ingesting and acting upon instructions from an untrusted external catalog. An attacker modifying this catalog could trick the agent into following malicious instructions or adopting dangerous tools.
  • Ingestion points: Step 3 in SKILL.md directs the agent to fetch and scan the remote CATALOG.md file.
  • Boundary markers: Absent; there are no instructions provided to the agent to disregard potential commands or treat the external catalog content as untrusted data.
  • Capability inventory: The skill is designed to find and execute other skills in the environment and uses the agent-memory-mcp tool for recording and retrieving operational data.
  • Sanitization: Absent; the agent is directed to scan categories and identify appropriate skills to use directly from the external source.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 09:20 PM
Security Audit — agent-trust-hub — antigravity-skill-orchestrator