review-skill
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches installation scripts for the Claude CLI from Anthropic's official domain and the
skill-validatortool from its GitHub repository. - [REMOTE_CODE_EXECUTION]: Performs piped execution of the Claude CLI installation script via bash. This is an expected installation method from a trusted vendor.
- [COMMAND_EXECUTION]: Executes the
skill-validatorandclaudecommand-line tools to process skill files. It also uses standard utilities likecat,ls, andmkdirfor environment setup and state persistence. - [PRIVILEGE_ESCALATION]: Includes instructions for setting executable permissions using
chmod +xduring manual tool installation. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided skill files for analysis, which presents a surface for instructions embedded in the analyzed data to influence the agent. • Ingestion points: Reads
SKILL.mdand referenced files at a path specified by the user in Step 4 and Step 5. • Boundary markers: No specific delimiters or 'ignore' instructions are used to isolate the analyzed content. • Capability inventory: Capable of executing shell commands (skill-validator,claude) and performing file system operations. • Sanitization: Ingested content is evaluated for quality without explicit sanitization or filtering of embedded instructions.
Audit Metadata