skill-best-practices
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requires the agent to run a local Python script (
scripts/validate-metadata.py) to ensure metadata compliance. - [INDIRECT_PROMPT_INJECTION]: The skill instructions create an attack surface where untrusted user input (the skill name and description) is interpolated into a command line template.
- Ingestion points: Step 1 in
SKILL.mdidentifies placeholders for metadata input provided during the authoring process. - Boundary markers: The instruction template uses double quotes (
"[name]") as a basic boundary, though these can be bypassed by shell metacharacters. - Capability inventory: The agent has the capability to execute
python3for script execution within thescripts/directory. - Sanitization: The
validate-metadata.pyscript performs regex validation on the input, but this occurs after the shell process has already handled the interpolation.
Audit Metadata