skills-expert
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides technical documentation and guidance for managing Claude Code skills. No malicious code, obfuscation, or unauthorized network operations were detected.
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface
- Ingestion points: The skill ingests untrusted data when reading external SKILL.md files or directory structures for debugging and validation purposes.
- Boundary markers: The instructions do not explicitly mandate the use of XML delimiters or specific boundary markers for the ingested content.
- Capability inventory: The skill is configured with broad file system permissions, including Read, Write, Glob, Grep, and Edit tools, which are necessary for its primary function of fixing and creating skills.
- Sanitization: No explicit sanitization or filtering of external file content is described in the skill prompt.
Audit Metadata