meta-skill-creation

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Local Script and Command Execution: The skill automates the development lifecycle by invoking local Python scripts (e.g., aggregate_benchmark, run_loop, package_skill) and shell utilities like nohup, kill, and cp. These tools are used to aggregate data, manage background processes for the evaluation viewer, and stage files during packaging.
  • Subagent Delegation: For testing and benchmarking, the skill instructs the agent to spawn subagents to run specific test prompts. This pattern allows for parallel evaluation of different skill versions but involves delegating execution to other AI instances.
  • Indirect Prompt Injection Surface: As a meta-tool, the skill ingests user-defined "test cases" and "intent" to generate and verify new skills. Since these user-provided inputs are ultimately processed by the agent and its subagents, there is an inherent surface for indirect prompt injection if malicious instructions are embedded within the test data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:44 PM
Security Audit — agent-trust-hub — meta-skill-creation