skill-creator

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides utility scripts (init_skill.py, package_skill.py) that perform local file system operations, including creating directory trees and writing boilerplate code files.
  • [PRIVILEGE_ESCALATION]: The initialization script (init_skill.py) programmatically sets executable permissions (chmod 755) on a dynamically generated template file (example.py).
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts user-defined names and paths to create new project structures. This ingestion point constitutes a surface where malformed input could potentially influence file system paths, although standard path resolution techniques are employed to mitigate risk.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 18, 2026, 02:05 PM
Security Audit — agent-trust-hub — skill-creator