skills/grupous/gpus/skill-creator/Gen Agent Trust Hub

skill-creator

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a benign utility for project scaffolding and contains no malicious instructions or hidden code.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied skill names and directory paths to generate template files. Evidence chain: 1. Ingestion points: skill_name and path arguments in 'scripts/init_skill.py'. 2. Boundary markers: Procedural template structure. 3. Capability inventory: Filesystem writes and directory creation in 'scripts/init_skill.py'; directory zipping in 'scripts/package_skill.py'. 4. Sanitization: Validation logic in 'scripts/quick_validate.py' enforces hyphen-case naming conventions and prevents the use of angle brackets in description fields, mitigating potential injection vectors during the creation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 09:21 AM
Security Audit — agent-trust-hub — skill-creator