skill-best-practices

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the agent to run a local Python script (scripts/validate-metadata.py) to ensure metadata compliance.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions create an attack surface where untrusted user input (the skill name and description) is interpolated into a command line template.
  • Ingestion points: Step 1 in SKILL.md identifies placeholders for metadata input provided during the authoring process.
  • Boundary markers: The instruction template uses double quotes ("[name]") as a basic boundary, though these can be bypassed by shell metacharacters.
  • Capability inventory: The agent has the capability to execute python3 for script execution within the scripts/ directory.
  • Sanitization: The validate-metadata.py script performs regex validation on the input, but this occurs after the shell process has already handled the interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — skill-best-practices