update-skills

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily instructional and establishes a framework for 'Preservation Audits' and 'Generalization' when moving skills from private to public environments.
  • [DATA_EXFILTRATION]: The skill explicitly mandates the removal of sensitive data before promotion to a marketplace. It includes 'hard rules' and 'Phase 6: Surface validation' checks to scrub project names, internal URLs, absolute home paths, and internal tool references (e.g., Grafana, Linear, Slack). This is a strong positive security control.
  • [PROMPT_INJECTION]: The instructions include standard instructional markers like 'IMPORTANT' and 'MUST/NEVER', but these are used in the context of maintaining documentation quality and information preservation, not for bypassing safety filters or overriding agent identity.
  • [COMMAND_EXECUTION]: The skill mentions using a tool called dex and provides a configuration for whitelisting its bash commands. These are localized management tasks within the user's environment and do not involve remote execution or privilege escalation.
  • [EXTERNAL_DOWNLOADS]: The references/skill-authoring-guidance.md file links to official documentation from Anthropic (platform.claude.com) and a specialized specification site (agentskills.io). These are well-known or directly relevant domain-specific resources and do not represent a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 02:53 PM
Security Audit — agent-trust-hub — update-skills