generating-python-installer
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied strings (such as application names, versions, and local paths) and embeds them into script templates for Batch, PowerShell, and Inno Setup.
- Ingestion points: User parameters are collected through a structured inquiry process defined in SKILL.md.
- Boundary markers: The skill requires the agent to explicitly confirm each parameter with the user and wait for a response before generating or suggesting scripts.
- Capability inventory: The generated scripts perform potentially impactful operations, including directory deletion (
rd /s /q), file deletion (Remove-Item -Force), and execution of compiler tools. - Sanitization: The instructions do not specify sanitization or validation logic for the user-supplied parameters before they are interpolated into the scripts.
- [DYNAMIC_EXECUTION]: The skill generates script files (
build_optimized.bat,slim_dist.ps1,analyze_dlls.py) and installer configurations at runtime based on the user's specific project needs. These are standard development templates used for local packaging tasks. - [COMMAND_EXECUTION]: The skill templates include commands for cleaning distribution environments, analyzing binary dependencies, and running the Nuitka compiler to build executable files.
Audit Metadata