agent-skill-generator
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external skill packages and conversation examples, creating a surface for embedded instructions in assessment targets. The risk is mitigated by explicit instructions to treat assessment targets as source artifacts and define clear side-effect boundaries.\n
- Ingestion points: External skill folders and repository files as described in SKILL.md.\n
- Boundary markers: Use of specific target profiles (portable, repo-bound) and side-effect boundaries.\n
- Capability inventory: File searching, file reading, and script execution.\n
- Sanitization: Explicit instructions to report unsafe validation steps and avoid following untrusted workflows.\n- [COMMAND_EXECUTION]: The agent is instructed to validate skills by executing bundled scripts. This functional capability is constrained by safety instructions that require the agent to assess safety before execution and report limitations where execution is unavailable or hazardous.
Audit Metadata