add-skill
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes standard shell commands such as
mkdirandlnto manage the local file system. Specifically, it symlinks skill directories from a central repository (~/Code/joelhooks/joelclaw/skills/) to various agent configuration directories like~/.claude/skills/and~/.pi/agent/skills/. - [COMMAND_EXECUTION]: Git integration is included to ensure skills are version-controlled, requiring the agent to perform
git addandgit commitoperations within the local repository. - [EXTERNAL_DOWNLOADS]: The skill describes a process for installing third-party skill packs using
npx -y skills add <owner>/<repo>. This involves downloading and executing code from external repositories via the npm package manager. - [INDIRECT_PROMPT_INJECTION]: As a meta-skill designed to generate new sets of instructions, it defines a template that other agents will eventually process. This introduces a vulnerability surface where if an agent populates the template with untrusted content or installs an external repository containing malicious instructions, it could lead to the sub-skill performing unintended actions. The template does, however, encourage the inclusion of a 'Rules' section for safety boundaries.
- Ingestion points: SKILL.md template fields (name, description, instructions) and external repository paths in the installation command.
- Boundary markers: The template uses Markdown headers (e.g., '#', '## Rules') to structure the instructions, though no explicit 'ignore embedded instructions' warnings are mandated.
- Capability inventory: The skill has access to directory creation (
mkdir), symlinking (ln), git operations, and package execution (npx). - Sanitization: There is no automated sanitization or validation of the content being written into the new SKILL.md files.
Audit Metadata