review-skill

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches installation scripts for the Claude CLI from Anthropic's official domain and the skill-validator tool from its GitHub repository.
  • [REMOTE_CODE_EXECUTION]: Performs piped execution of the Claude CLI installation script via bash. This is an expected installation method from a trusted vendor.
  • [COMMAND_EXECUTION]: Executes the skill-validator and claude command-line tools to process skill files. It also uses standard utilities like cat, ls, and mkdir for environment setup and state persistence.
  • [PRIVILEGE_ESCALATION]: Includes instructions for setting executable permissions using chmod +x during manual tool installation.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided skill files for analysis, which presents a surface for instructions embedded in the analyzed data to influence the agent. • Ingestion points: Reads SKILL.md and referenced files at a path specified by the user in Step 4 and Step 5. • Boundary markers: No specific delimiters or 'ignore' instructions are used to isolate the analyzed content. • Capability inventory: Capable of executing shell commands (skill-validator, claude) and performing file system operations. • Sanitization: Ingested content is evaluated for quality without explicit sanitization or filtering of embedded instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 08:33 AM
Security Audit — agent-trust-hub — review-skill