skill-creator

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes Python scripts (init_skill.py, package_skill.py) designed to be executed by the agent to automate local file system operations such as directory creation, file writing, and ZIP packaging. These operations are restricted to the local workspace and are central to the skill's purpose as a development tool.
  • [DYNAMIC_EXECUTION]: The quick_validate.py script utilizes yaml.safe_load() for parsing user-provided metadata in SKILL.md files. This is a recommended security practice to prevent arbitrary code execution during the deserialization of YAML data.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of new skills from user input, which presents a surface for processing untrusted data.
  • Ingestion points: User instructions and requirements for new skill creation processed in SKILL.md.
  • Boundary markers: The skill architecture mandates a YAML frontmatter section in SKILL.md which acts as a structural delimiter.
  • Capability inventory: Local file system operations (mkdir, write_text) and ZIP packaging (zipfile) are provided via distributed scripts.
  • Sanitization: The quick_validate.py script enforces structural validation, naming conventions, and length limits on skill metadata to ensure consistency and prevent malformed inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — skill-creator