skill-intake-lifecycle
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use various shell commands for administrative tasks, including 'npx skills add', 'npx skills remove', 'jq', and 'date' to manage the local skill environment and record lifecycle events.\n- [EXTERNAL_DOWNLOADS]: Third-party skills are downloaded and installed into the provisional '
/.agents' directory using the 'npx skills add' command as part of the intake process.\n- [DATA_EXFILTRATION]: The skill reads and writes to sensitive files in the user's home directory, specifically '/.agents/.skill-lock.json' and '~/.agents/skill-journal.jsonl', to track installation state and governance history. These operations are limited to the skill's management scope.\n- [PROMPT_INJECTION]: Processing metadata from external skills, such as rationales and evidence strings from the journal, introduces an indirect prompt injection surface.\n - Ingestion points: Data is read from the lock file and journal logs in '~/.agents/'.\n
- Boundary markers: The instructions do not specify the use of delimiters when the agent processes or reports on skill metadata during review.\n
- Capability inventory: The skill has access to package management tools and file manipulation via shell commands.\n
- Sanitization: While 'jq' is used to ensure structural integrity of JSON log entries, the textual content of skill rationales is not sanitized for malicious instructions.
Audit Metadata