generating-python-installer

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied strings (such as application names, versions, and local paths) and embeds them into script templates for Batch, PowerShell, and Inno Setup.
  • Ingestion points: User parameters are collected through a structured inquiry process defined in SKILL.md.
  • Boundary markers: The skill requires the agent to explicitly confirm each parameter with the user and wait for a response before generating or suggesting scripts.
  • Capability inventory: The generated scripts perform potentially impactful operations, including directory deletion (rd /s /q), file deletion (Remove-Item -Force), and execution of compiler tools.
  • Sanitization: The instructions do not specify sanitization or validation logic for the user-supplied parameters before they are interpolated into the scripts.
  • [DYNAMIC_EXECUTION]: The skill generates script files (build_optimized.bat, slim_dist.ps1, analyze_dlls.py) and installer configurations at runtime based on the user's specific project needs. These are standard development templates used for local packaging tasks.
  • [COMMAND_EXECUTION]: The skill templates include commands for cleaning distribution environments, analyzing binary dependencies, and running the Nuitka compiler to build executable files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — generating-python-installer