creating-skills

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill procedure involves executing local repository tools such as make, skill-new, skill-lint, and make test. These commands are used to automate the scaffolding of new files and the verification of the project's logic and structure.- [INDIRECT_PROMPT_INJECTION]: During the scaffolding phase in SKILL.md, user-supplied arguments for 'CATEGORY' and 'NAME' are interpolated directly into shell commands. This introduces a potential command injection surface if these variables are not correctly escaped or validated by the underlying scripts.
  • Ingestion points: The CATEGORY and NAME parameters are derived from user input and used in shell commands in Step 2 of SKILL.md.
  • Boundary markers: The instructions do not define any specific input validation or boundary markers to prevent the execution of malicious shell metacharacters.
  • Capability inventory: The skill environment possesses the capability to execute shell commands and modify local repository files.
  • Sanitization: There is no evidence of sanitization, escaping, or filtering of the user-provided variables within the skill's instructions.- [DYNAMIC_EXECUTION]: The skill is designed to generate new functional code and documentation (SKILL.md and associated scripts) from templates. While this is the intended use case, it involves the dynamic creation of executable assets within the repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 07:16 PM
Security Audit — agent-trust-hub — creating-skills