skills/ethan-rio/skills/skill-creator/Gen Agent Trust Hub

skill-creator

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs Python's subprocess module across several scripts, including scripts/run_eval.py, scripts/improve_description.py, and eval-viewer/generate_review.py. These scripts execute the claude command-line interface to perform evaluation runs and optimization tasks, as well as system utilities like lsof to manage the local review server. These operations are core to the skill's lifecycle management functions.
  • [EXTERNAL_DOWNLOADS]: The eval-viewer/viewer.html file includes a script reference to the SheetJS library (xlsx.full.min.js) hosted on cdn.sheetjs.com. This is used to render Excel outputs within the browser-based review tool. SheetJS is a well-known and recognized service for spreadsheet processing in web applications.
  • [INDIRECT_PROMPT_INJECTION]: The skill features a surface for indirect prompt injection as it ingests and processes user-provided test prompts and feedback from files like evals/evals.json and feedback.json. This data is used to drive the AI agent's evaluation and improvement loops. This capability is intrinsic to the tool's purpose of prompt engineering and skill optimization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:55 AM
Security Audit — agent-trust-hub — skill-creator