add-new-skills-to-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses a local script
download_from_github.pyto fetch content from user-provided GitHub repositories (<repo-url>). While GitHub is a common service, fetching content from arbitrary repositories introduces a vector for untrusted data ingestion. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read and understand the
SKILL.mdfile from downloaded external repositories to determine how to update documentation and integrate the skill. This creates a surface for indirect prompt injection where a malicious skill file could contain instructions to subvert the agent's behavior during the integration process. - Ingestion points: External
SKILL.mdfiles downloaded from GitHub repositories as described in Step 1 and Step 2. - Boundary markers: Absent. There are no instructions to isolate the content of the downloaded skill or ignore embedded instructions during the processing phase.
- Capability inventory: The skill possesses capabilities to execute a Python downloader script, read local files, and perform extensive writes to documentation files (
README.md,AGENTS.md,*.mdx) and configuration files (skill-source.json). - Sanitization: Absent. The agent is encouraged to directly process and interpret the markdown content of the external skill without validation or escaping.
Audit Metadata