skill-development

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes Python utilities (init_skill.py, package_skill.py) that perform local file system operations. These tools facilitate the creation of skill directories, writing of template files, and the zipping of skill folders for distribution, which are standard operations for development workflows.
  • [DYNAMIC_EXECUTION]: During the initialization of a new skill, init_skill.py generates a Python script from a hardcoded template and updates its file permissions to be executable. This is a common pattern for project scaffolding tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides scripts that ingest and process metadata from other skill files.
  • Ingestion points: quick_validate.py and package_skill.py read SKILL.md files from local directories.
  • Boundary markers: No specific delimiters are implemented in the scripts to isolate file content from execution context.
  • Capability inventory: The utility scripts have permissions to create directories, write files, and package archives.
  • Sanitization: quick_validate.py enforces regex patterns on skill names and descriptions to prevent invalid formatting and restricted characters.
  • [EXTERNAL_DOWNLOADS]: The documentation refers to well-known external services and developer tools, including GitHub for PR workflows and Playwright for testing examples. These references are used for instructional purposes and do not trigger unauthorized remote downloads or execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — skill-development