skill-scout

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands such as find, grep, and gh (GitHub CLI) to search for existing skills. Specifically, it uses user-derived keywords and synonyms directly in commands like grep -iE "keyword|synonym", which could lead to command injection if the generated keywords contain shell metacharacters.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to ingest and process SKILL.md files from external sources (GitHub, marketplaces, and web searches).
  • Ingestion points: Processes SKILL.md files retrieved from local marketplace directories and remote GitHub repositories.
  • Boundary markers: The skill lacks technical boundary markers (like XML tags) for external content, though it includes a "Vet External Matches" step to manually review instructions.
  • Capability inventory: The skill possesses shell execution capabilities (find, grep, gh) and web search capabilities.
  • Sanitization: While Step 4 instructs the agent to manually look for "unexpected shell commands" or "credential handling," there is no automated sanitization or sandboxing for the ingested markdown content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — skill-scout