audit-skill-completeness

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes untrusted data from external skill directories.
  • Ingestion points: Reading SKILL.md and other files within the target skill's path.
  • Boundary markers: The workflow lacks delimiters or specific instructions to treat audited content as data rather than instructions, potentially allowing a malicious skill to hijack the auditing process.
  • Capability inventory: The agent can read arbitrary files in the target path and write generated markdown reports to the local .claude/audits/ directory.
  • Sanitization: The skill does not validate or sanitize the content of the files it reads before evaluating them.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 08:41 AM
Security Audit — agent-trust-hub — audit-skill-completeness