skill-factory
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: Instructions in SKILL.md require the execution of a local validation script (bash scripts/validate_skill_authoring_family.sh) when specific authoring families are modified. This command is part of an internal project integrity and policy enforcement workflow.
- [PROMPT_INJECTION]: The references/evals.yaml file contains simulated injection strings such as 'ignore previous instructions'. These are correctly identified as defensive evaluation prompts used to test the agent's safety boundaries rather than malicious instructions meant to subvert behavior.
- [EXTERNAL_DOWNLOADS]: The skill identifies curated skills from openai/skills as installation sources. This refers to a well-known service and is used for informational/operational context within a developer-focused tool.
Audit Metadata