remove-old-skills-from-workflow

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill guides the agent to perform destructive file system operations using rm -rf. While intended for cleaning up workflow directories, the use of this command with user-supplied variable names poses a risk of accidental or malicious data loss if the path is not strictly controlled by the agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents a vulnerability surface by ingesting external user data and utilizing it in shell operations. Ingestion points: The user provides the name of a skill to be removed (e.g., 'ppt-creator'). Boundary markers: There are no boundary markers or 'ignore' instructions to help the agent distinguish between a valid skill name and a malicious string. Capability inventory: The skill uses shell execution capabilities for searching (grep) and directory removal (rm). Sanitization: The instructions do not include requirements for the agent to sanitize the input, validate the resulting path, or check for path traversal sequences like ../, which could lead to deleting files outside the intended directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:05 PM
Security Audit — agent-trust-hub — remove-old-skills-from-workflow