sgc-skill-distiller
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/collect-source-evidence.pyuses thesubprocessmodule to executegitcommands (e.g.,git log,git rev-parse). These executions are limited to local metadata extraction from a user-provided project directory and do not involve shell interpolation or remote command execution. - [INDIRECT_PROMPT_INJECTION]: The skill has an indirect prompt injection attack surface because it processes untrusted project documentation and commit history. However, this risk is mitigated by explicit instructions in the
SKILL.mdandreferences/distillation-lens.mdfiles that require the agent to filter out private information (names, keys, credentials) and focus on distilling abstract logic. - [DYNAMIC_EXECUTION]: The skill includes a validation script
scripts/validate_skill.pythat usesyaml.safe_loadto parse metadata. This follows security best practices by avoiding unsafe YAML loading techniques that could lead to arbitrary code execution.
Audit Metadata