skill-creator

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a pipeline for content that could potentially contain malicious instructions (drafted skills). However, the instructions mandate an 'explicit human ship and purpose_pass' before any content is moved into the functional 'skills/' directory, effectively mitigating the risk of automated injection.- [COMMAND_EXECUTION]: The workflow performs file system operations including reading from '.skill-proposals/', writing to 'skills/', and updating project indices. It explicitly forbids high-risk actions such as 'npx skills install' or git commits, maintaining a restricted execution environment.- [SAFE]: No obfuscation, data exfiltration patterns, or unauthorized remote code execution were identified. The skill focuses on structured local file management with clear human-in-the-loop requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 04:07 PM
Security Audit — agent-trust-hub — skill-creator