creating-skills
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill procedure involves executing local repository tools such as
make,skill-new,skill-lint, andmake test. These commands are used to automate the scaffolding of new files and the verification of the project's logic and structure.- [INDIRECT_PROMPT_INJECTION]: During the scaffolding phase inSKILL.md, user-supplied arguments for 'CATEGORY' and 'NAME' are interpolated directly into shell commands. This introduces a potential command injection surface if these variables are not correctly escaped or validated by the underlying scripts. - Ingestion points: The
CATEGORYandNAMEparameters are derived from user input and used in shell commands in Step 2 ofSKILL.md. - Boundary markers: The instructions do not define any specific input validation or boundary markers to prevent the execution of malicious shell metacharacters.
- Capability inventory: The skill environment possesses the capability to execute shell commands and modify local repository files.
- Sanitization: There is no evidence of sanitization, escaping, or filtering of the user-provided variables within the skill's instructions.- [DYNAMIC_EXECUTION]: The skill is designed to generate new functional code and documentation (
SKILL.mdand associated scripts) from templates. While this is the intended use case, it involves the dynamic creation of executable assets within the repository.
Audit Metadata