zmm-skillify
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local shell script
bash zmm/scripts/list-skills.shduring the self-check phase (Step 4) to identify overlapping functionalities with existing skills. - [INDIRECT_PROMPT_INJECTION]: The skill represents an indirect prompt injection surface as it ingests untrusted data from the current conversation history to generate persistent instructions for new skills. Ingestion points: Session history, user-described workflows, and memory files in
{config.paths.memory}/zmm-skillify/. Boundary markers: The skill does not define specific delimiters for separating user-provided workflow data from generated instructions. Capability inventory: The skill writes new directories and files to the local filesystem and executes local bash scripts. Sanitization: No explicit sanitization or filtering of the ingested session data is mentioned before incorporation into new skill files.
Audit Metadata