ln-81-skill-reviewer

Warn

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and act upon instructions and contracts found within external repositories (e.g., "Read the repository instructions, skill contracts, and every configured host catalog before judging"). This creates a vulnerability where a malicious repository can provide instructions that override the agent's intended review logic.\n- [DYNAMIC_EXECUTION]: The skill directs the agent to "Discover and run every repository-required skill validator" found within the repository being reviewed. This leads to the execution of arbitrary scripts or binaries provided by the untrusted repository, potentially compromising the agent's environment.\n- [COMMAND_EXECUTION]: The skill makes use of shell commands to interact with the repository and execute validators, which could be exploited if repository-controlled strings (like file paths or validator names) are not properly handled.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 5, 2026, 07:50 AM
Security Audit — agent-trust-hub — ln-81-skill-reviewer