skill-creator
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Multiple Python scripts within the skill utilize the
subprocessmodule to perform system tasks.scripts/run_eval.pyandscripts/improve_description.pyexecute theclaudeCLI to run subagent evaluations and improve skill descriptions. Additionally,eval-viewer/generate_review.pyruns thelsofutility to identify and manage occupied network ports. - [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes user-defined skill drafts and test prompts without automated sanitization, though it mitigates this with clear security instructions.
- Ingestion points: Processes user-provided intents and skill drafts in
SKILL.mdand test queries inevals/evals.json. - Boundary markers: Uses the 'eval-viewer' to facilitate manual human review of all generated content.
- Capability inventory: Utilizes
subprocessfor executing theclaudeCLI and has broad file system read/write access. - Sanitization: Lacks explicit input sanitization, relying instead on integrated 'Garde-fous de sécurité' guidelines that warn against creating destructive or malicious skills.
Audit Metadata