skill-security-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill references phrases such as "ignore all instructions" and "reveal the system prompt" in its criteria for auditing other skills. These are used as benchmarks for evaluation and do not represent active injection attempts within this skill's own operations.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted skill content from third parties. While this presents an indirect injection surface, the skill has no dangerous tools (network or file access) to be exploited, and the process includes human review steps.- [COMMAND_EXECUTION]: The prose mentions a command "node scripts/skill-audit.mjs" in the context of a workflow recommendation for a repository's CI pipeline. The skill does not actually call this command itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 09:40 PM
Security Audit — agent-trust-hub — skill-security-auditor