skill-creator
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use shell commands including
mkdir,cat, andechoto create and manage a workflow workspace in the/tmpdirectory. This behavior is used to maintain state and avoid context overflow when processing long documents. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external, untrusted source documents provided by the user, which presents a surface for indirect prompt injection.
- Ingestion points: Document content is read into the agent's context via file-read operations described in
resources/component-extraction.md. - Boundary markers: The instructions do not define specific delimiters or "ignore" instructions to prevent the agent from following directives found within the analyzed text.
- Capability inventory: The skill utilizes shell command execution for file and directory management.
- Sanitization: No content sanitization or validation steps are performed on the ingested text before analysis.
Audit Metadata