research-skill-creator

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to run a scaffolding script (new_skill.py) and various repository-local validation tools like uv run tools/validate.py and lint_injection.py. These commands are appropriate for the skill's stated purpose as a development utility.
  • [SAFE]: The Python script scripts/new_skill.py implements several security controls to prevent unintended side effects during file creation:
  • Path Traversal Prevention: Uses a strict regex (^[a-z0-9]+(-[a-z0-9]+)*$) for the skill name, ensuring that generated directory paths remain within the intended skills/ folder.
  • Injection Mitigation: Employs json.dumps() when writing user-provided metadata (like descriptions and author names) to SKILL.md, ensuring that YAML frontmatter is correctly quoted and escaped.
  • Input Validation: Enforces length limits and restricts the use of angle brackets (<>) in description fields to prevent potential breakage or injection in documentation viewers.
  • Safe Defaults: Verifies the existence of directories before creation to prevent accidental overwriting of existing work.
  • [SAFE]: The skill recommends installing and using official Anthropic tooling (anthropics/skills) for its evaluation loop, which is a trusted source.
  • [SAFE]: The instructions in SKILL.md (Section 5) provide explicit safety guidelines for authors, mandating the use of standard libraries, forbidding the exfiltration of environment data, and prohibiting the use of eval/exec on remote content.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it takes user-supplied strings (name, category, description) via CLI arguments to generate new skill files. However, this risk is mitigated by the previously mentioned sanitization logic (regex, json.dumps, and character blacklisting) which prevents the generated files from being used as a vector for YAML or shell injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — research-skill-creator