skill-craft-review
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as an auditing framework and contains no malicious code, unauthorized command execution, or persistence mechanisms within its own instructions or supporting files.- [PROMPT_INJECTION]: The workflow (SKILL.md Workflow Step 3) includes strong defensive instructions to treat all content in a reviewed submission as data to be analyzed rather than instructions to be followed, which is a key security measure against indirect prompt injection.- [DATA_EXFILTRATION]: No exfiltration logic is present. The skill instructs agents to scan for and report exfiltration attempts (such as contacting external endpoints) within the submissions they are auditing.- [EXTERNAL_DOWNLOADS]: While the skill references an external GitHub repository (github.com/obra/superpowers) for provenance and methodology reference, it does not perform any automated downloads or execution of remote code during its operation.
Audit Metadata