create-genre-skill-skeletons

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes multiple reference files (e.g., references/standard-genre-skill-list.md, platform-specific migration ledgers in references/section-ledgers/) and interpolates their content into newly generated SKILL.md files. This creates a surface where instructions embedded in those data files could influence the generated output.
  • Ingestion points: Reference files read via read_file in the references/ directory, including platform ledgers and standard skill lists.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to disregard potential instructions within the reference data.
  • Capability inventory: The skill utilizes file reading and file/directory creation capabilities.
  • Sanitization: No sanitization or validation of the content within the reference files is performed before interpolation into generated skills.
  • [DYNAMIC_EXECUTION]: The skill dynamically generates SKILL.md files from a template (references/genre-skill-skeleton-template.md). Since SKILL.md files contain instructions executed by the AI agent, this constitutes a script generation pattern. This is a low-risk architectural feature necessary for the skill's primary purpose as a scaffolding tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 01:41 PM
Security Audit — agent-trust-hub — create-genre-skill-skeletons