skill-creator

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes several Python scripts (scripts/init_skill.py, scripts/generate_openai_yaml.py, and scripts/quick_validate.py) designed for local automation. These scripts perform standard file system operations such as directory creation, writing markdown templates, and generating YAML configuration files.
  • [SAFE]: The utility scripts use yaml.safe_load() for parsing skill frontmatter and metadata, adhering to security best practices to prevent arbitrary code execution during deserialization.
  • [SAFE]: The script scripts/init_skill.py uses chmod(0o755) to set executable permissions on newly created example scripts. This is standard behavior for a developer initialization tool and does not constitute a privilege escalation risk.
  • [SAFE]: No network communication, external downloads, or patterns of data exfiltration were found within the skill's instructions or supporting scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — skill-creator