skill-composer-studio

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to chain multiple existing skills into custom workflows where the output of one step serves as the input for the next. This architecture creates a surface for multi-step indirect prompt injection attacks if any skill in the sequence processes untrusted external data (such as web content or external files).
  • Ingestion points: User-provided workflow descriptions and the outputs from preceding skill executions in the defined sequence.
  • Boundary markers: The instructions lack specific requirements for delimiters or instructions to treat tool outputs as data rather than instructions during handoffs.
  • Capability inventory: The skill claims the authority to orchestrate and execute workflows involving the entire catalog of available skills, which may include file operations, network access, or code execution depending on the specific tools composed.
  • Sanitization: No explicit sanitization, validation, or escaping logic is defined for data being passed between steps in a workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 07:25 AM
Security Audit — agent-trust-hub — skill-composer-studio