skills/hunix/hoc-republic/skill-forge/Gen Agent Trust Hub

skill-forge

Warn

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a tool skill_forge_create that automates the creation of files within the .agents/skills/ directory. This allows the agent to modify its own capabilities and persist new logic implementations on the filesystem.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through the objective parameter. Because this parameter is used to generate the logic and instructions for new skills, a crafted input could trick the agent into forging skills that contain malicious behavior or bypass safety constraints.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 18, 2026, 01:07 AM
Security Audit — agent-trust-hub — skill-forge