skills/iamzifei/zmm/zmm-skillify/Gen Agent Trust Hub

zmm-skillify

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local shell script bash zmm/scripts/list-skills.sh during the self-check phase (Step 4) to identify overlapping functionalities with existing skills.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents an indirect prompt injection surface as it ingests untrusted data from the current conversation history to generate persistent instructions for new skills. Ingestion points: Session history, user-described workflows, and memory files in {config.paths.memory}/zmm-skillify/. Boundary markers: The skill does not define specific delimiters for separating user-provided workflow data from generated instructions. Capability inventory: The skill writes new directories and files to the local filesystem and executes local bash scripts. Sanitization: No explicit sanitization or filtering of the ingested session data is mentioned before incorporation into new skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 07:32 AM