skill-creator
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the 'claude' CLI tool to perform evaluations and optimize descriptions. These calls are performed using the subprocess module with arguments passed as a list, which prevents shell injection.
- Evidence: Found in
scripts/improve_description.py(line 62) andscripts/run_eval.py(line 78). - [COMMAND_EXECUTION]: The results viewer script executes the 'lsof' command to manage its local server's port allocation.
- Evidence: Found in
eval-viewer/generate_review.py(line 197). - [DATA_EXFILTRATION]: The skill starts a local HTTP server on '127.0.0.1' to allow the user to review evaluation results and feedback. This server reads files from the designated workspace directory to render them in the viewer.
- Evidence: Found in
eval-viewer/generate_review.py(line 228) and the accompanyingviewer.html. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by interpolating user-provided skill content and evaluation queries into prompts used for description optimization. It mitigates this risk by wrapping external content in XML-like tags (e.g.,
<skill_content>,<scores_summary>) to provide clear boundaries for the model. - Ingestion points:
scripts/improve_description.pyreads data fromeval_resultsandskill_content. - Boundary markers: Present in the
improve_descriptionfunction's prompt template. - Capability inventory: Spawns subagents, writes files to
.claude/commands/, and executes local CLI commands. - Sanitization: Uses structured XML-style delimiters to separate untrusted data from instructions.
- [SAFE]: The skill uses 'cdn.sheetjs.com' to load the SheetJS library for rendering Excel files in the results viewer. This is a well-known service for client-side spreadsheet processing.
- Evidence: Found in
eval-viewer/viewer.html(line 8).
Audit Metadata