research-skill-creator
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to run a scaffolding script (
new_skill.py) and various repository-local validation tools likeuv run tools/validate.pyandlint_injection.py. These commands are appropriate for the skill's stated purpose as a development utility. - [SAFE]: The Python script
scripts/new_skill.pyimplements several security controls to prevent unintended side effects during file creation: - Path Traversal Prevention: Uses a strict regex (
^[a-z0-9]+(-[a-z0-9]+)*$) for the skill name, ensuring that generated directory paths remain within the intendedskills/folder. - Injection Mitigation: Employs
json.dumps()when writing user-provided metadata (like descriptions and author names) toSKILL.md, ensuring that YAML frontmatter is correctly quoted and escaped. - Input Validation: Enforces length limits and restricts the use of angle brackets (
<>) in description fields to prevent potential breakage or injection in documentation viewers. - Safe Defaults: Verifies the existence of directories before creation to prevent accidental overwriting of existing work.
- [SAFE]: The skill recommends installing and using official Anthropic tooling (
anthropics/skills) for its evaluation loop, which is a trusted source. - [SAFE]: The instructions in
SKILL.md(Section 5) provide explicit safety guidelines for authors, mandating the use of standard libraries, forbidding the exfiltration of environment data, and prohibiting the use ofeval/execon remote content. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it takes user-supplied strings (name, category, description) via CLI arguments to generate new skill files. However, this risk is mitigated by the previously mentioned sanitization logic (regex,
json.dumps, and character blacklisting) which prevents the generated files from being used as a vector for YAML or shell injection.
Audit Metadata