sgc-skill-distiller

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/collect-source-evidence.py uses the subprocess module to execute git commands (e.g., git log, git rev-parse). These executions are limited to local metadata extraction from a user-provided project directory and do not involve shell interpolation or remote command execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an indirect prompt injection attack surface because it processes untrusted project documentation and commit history. However, this risk is mitigated by explicit instructions in the SKILL.md and references/distillation-lens.md files that require the agent to filter out private information (names, keys, credentials) and focus on distilling abstract logic.
  • [DYNAMIC_EXECUTION]: The skill includes a validation script scripts/validate_skill.py that uses yaml.safe_load to parse metadata. This follows security best practices by avoiding unsafe YAML loading techniques that could lead to arbitrary code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:09 PM
Security Audit — agent-trust-hub — sgc-skill-distiller