ns-skill-creator

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes npx @nextstage-brasil/harness sync to synchronize symlinks within the project's .claude/skills/ directory. This is a vendor-specific tool used for its documented purpose of ensuring skill discovery.
  • [EXTERNAL_DOWNLOADS]: The skill references and utilizes scripts from the anthropics/skills repository. This is a trusted organization, and the integration follows the standard workflow for the upstream skill-creator tool.
  • [PROMPT_INJECTION]: The skill acts as an ingestion surface for indirect prompt injection because it processes user-defined intents to draft new agent instructions (SKILL.md). However, this is the primary purpose of the skill, and it incorporates a review-based eval loop (eval-viewer) to mitigate risks through human oversight.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 08:49 PM
Security Audit — agent-trust-hub — ns-skill-creator