write-a-skill

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill serves as a template and workflow for generating new skills based on user requirements, which constitutes a vulnerability surface for untrusted data to influence the generated output.
  • [DYNAMIC_EXECUTION]: The instructions include a validation step requiring the agent to execute modified helper scripts to verify skill behavior, which is a form of runtime code execution.
  • [NO_CODE]: The analyzed content is composed entirely of markdown instructions and does not contain any embedded scripts, binaries, or external dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:14 PM
Security Audit — agent-trust-hub — write-a-skill