skill-creator
Warn
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local shell scripts (e.g.,
scripts/validate-skill-yaml.sh) to perform content and metadata validation. - [COMMAND_EXECUTION]: It performs file system modifications including directory creation (
mkdir -p) and dynamic file generation usingsedbased on user input. - [COMMAND_EXECUTION]: Modifies system configuration by creating symbolic links (
ln -sf) in user-specific configuration directories (e.g.,~/.copilot/skills/) to enable global installation of new skills. - [DATA_EXFILTRATION]: Accesses personal information from local git configuration (
git config user.name,git config user.email) to populate metadata in generated files. - [SAFE]: References official development documentation and guidelines from Anthropic's public repository.
- [PROMPT_INJECTION]: The skill accepts free-form user descriptions and interpolates them directly into generated instruction files, which creates a potential surface for indirect prompt injection in the resulting skills.
Audit Metadata