skill-forge
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local shell script (
scripts/validate-skill.sh) to perform structural and safety validation on the generated skill artifacts. It also utilizes shell hooks to enforce length limits on generated files, ensuring they remain within safe context boundaries.\n- [EXTERNAL_DOWNLOADS]: The skill is designed to crawl external documentation URLs and GitHub repositories to gather necessary context for skill generation. This network activity is restricted to research purposes and follows a prioritized crawl order defined in the instructions.\n- [PROMPT_INJECTION]: The skill processes untrusted data from the web during its research phase, creating a surface for indirect prompt injection. This is mitigated by a multi-stage validation process:\n - Ingestion points: Data enters the agent's context through URL crawling of official documentation (Phase 1A).\n
- Boundary markers: The agent is instructed to use
<!-- VERIFY: -->tags to highlight unconfirmed information and uses structured YAML/Markdown templates to segregate data.\n - Capability inventory: The skill has permissions to write files to specific skill directories and run validation scripts, but destructive actions or broad autonomy are explicitly forbidden in its safety guidelines.\n
- Sanitization: The skill includes a comprehensive validation script and authoring guidelines that scan for and block unsafe behavioral patterns, such as 'unbounded autonomy' or 'escalation suppression', in the resulting output.
Audit Metadata