skill-forge

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local shell script (scripts/validate-skill.sh) to perform structural and safety validation on the generated skill artifacts. It also utilizes shell hooks to enforce length limits on generated files, ensuring they remain within safe context boundaries.\n- [EXTERNAL_DOWNLOADS]: The skill is designed to crawl external documentation URLs and GitHub repositories to gather necessary context for skill generation. This network activity is restricted to research purposes and follows a prioritized crawl order defined in the instructions.\n- [PROMPT_INJECTION]: The skill processes untrusted data from the web during its research phase, creating a surface for indirect prompt injection. This is mitigated by a multi-stage validation process:\n
  • Ingestion points: Data enters the agent's context through URL crawling of official documentation (Phase 1A).\n
  • Boundary markers: The agent is instructed to use <!-- VERIFY: --> tags to highlight unconfirmed information and uses structured YAML/Markdown templates to segregate data.\n
  • Capability inventory: The skill has permissions to write files to specific skill directories and run validation scripts, but destructive actions or broad autonomy are explicitly forbidden in its safety guidelines.\n
  • Sanitization: The skill includes a comprehensive validation script and authoring guidelines that scan for and block unsafe behavioral patterns, such as 'unbounded autonomy' or 'escalation suppression', in the resulting output.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — skill-forge