skill-architect
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest user-provided workflows, task descriptions, and requirements to generate new AI agent instructions (SKILL.md files).
- Ingestion points: User input provided during the conversational 'interview' phase and existing code patterns shared by the user.
- Boundary markers: The skill relies on structured instructions and templates to guide the AI, though it does not implement formal technical delimiters for user input within its internal prompts.
- Capability inventory: The skill possesses the ability to write files to the local system (
Writetool) and execute shell commands (Bashtool) for validation. - Sanitization: The skill includes a local script,
scripts/validate-skill.py, which provides automated sanitization by checking generated content for dangerous patterns such as system command execution and dynamic code evaluation before the skill is considered complete. - [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to execute a local validation script as part of its standard workflow. - Evidence: Instructions in
SKILL.mdandREADME.mddirect the agent to executepython scripts/validate-skill.pyagainst the directory of the newly created skill. - Security Context: The validation script contains string literals of dangerous commands (e.g.,
rm -rf /,eval(),os.system()) used as regex patterns to detect and flag potential security risks in the skills it audits. These patterns are used for static analysis and do not represent executable malicious code within the skill itself.
Audit Metadata