skill-scout
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands such as
find,grep, andgh(GitHub CLI) to search for existing skills. Specifically, it uses user-derived keywords and synonyms directly in commands likegrep -iE "keyword|synonym", which could lead to command injection if the generated keywords contain shell metacharacters. - [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to ingest and process
SKILL.mdfiles from external sources (GitHub, marketplaces, and web searches). - Ingestion points: Processes
SKILL.mdfiles retrieved from local marketplace directories and remote GitHub repositories. - Boundary markers: The skill lacks technical boundary markers (like XML tags) for external content, though it includes a "Vet External Matches" step to manually review instructions.
- Capability inventory: The skill possesses shell execution capabilities (
find,grep,gh) and web search capabilities. - Sanitization: While Step 4 instructs the agent to manually look for "unexpected shell commands" or "credential handling," there is no automated sanitization or sandboxing for the ingested markdown content.
Audit Metadata