skill-creator
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes Python scripts (
init_skill.py,package_skill.py) designed to be executed by the agent to automate local file system operations such as directory creation, file writing, and ZIP packaging. These operations are restricted to the local workspace and are central to the skill's purpose as a development tool. - [DYNAMIC_EXECUTION]: The
quick_validate.pyscript utilizesyaml.safe_load()for parsing user-provided metadata inSKILL.mdfiles. This is a recommended security practice to prevent arbitrary code execution during the deserialization of YAML data. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of new skills from user input, which presents a surface for processing untrusted data.
- Ingestion points: User instructions and requirements for new skill creation processed in
SKILL.md. - Boundary markers: The skill architecture mandates a YAML frontmatter section in
SKILL.mdwhich acts as a structural delimiter. - Capability inventory: Local file system operations (
mkdir,write_text) and ZIP packaging (zipfile) are provided via distributed scripts. - Sanitization: The
quick_validate.pyscript enforces structural validation, naming conventions, and length limits on skill metadata to ensure consistency and prevent malformed inputs.
Audit Metadata