skill-best-practices

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local validation script ('scripts/validate-metadata.py') with user-provided arguments. This is a legitimate functional requirement for the skill's stated purpose and uses a locally bundled script rather than external code.
  • [PROMPT_INJECTION]: The skill processes untrusted user data (skill name and description) by interpolating it into a shell command for validation. While this represents a surface for indirect prompt injection, it is used for a restricted local task.
  • Ingestion points: User-provided metadata strings in SKILL.md.
  • Boundary markers: Arguments are wrapped in double quotes in the command template.
  • Capability inventory: Execution of a local Python script for metadata validation.
  • Sanitization: Not explicitly specified in the instructions, but the command structure follows standard CLI patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — skill-best-practices