skill-best-practices
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a local validation script ('scripts/validate-metadata.py') with user-provided arguments. This is a legitimate functional requirement for the skill's stated purpose and uses a locally bundled script rather than external code.
- [PROMPT_INJECTION]: The skill processes untrusted user data (skill name and description) by interpolating it into a shell command for validation. While this represents a surface for indirect prompt injection, it is used for a restricted local task.
- Ingestion points: User-provided metadata strings in SKILL.md.
- Boundary markers: Arguments are wrapped in double quotes in the command template.
- Capability inventory: Execution of a local Python script for metadata validation.
- Sanitization: Not explicitly specified in the instructions, but the command structure follows standard CLI patterns.
Audit Metadata