write-a-skill
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill serves as a template and workflow for generating new skills based on user requirements, which constitutes a vulnerability surface for untrusted data to influence the generated output.
- [DYNAMIC_EXECUTION]: The instructions include a validation step requiring the agent to execute modified helper scripts to verify skill behavior, which is a form of runtime code execution.
- [NO_CODE]: The analyzed content is composed entirely of markdown instructions and does not contain any embedded scripts, binaries, or external dependencies.
Audit Metadata