skill-card-generator

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/discover_assets.py uses subprocess.run to execute various git commands (git describe, git log, git remote) to gather repository metadata. While these commands are limited to local repository operations, they represent a shell execution surface triggered by the agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to ingest and analyze external directories and files provided via $ARGUMENTS to generate governance cards. This creates a vulnerability where malicious instructions or deceptive content embedded in a target skill's SKILL.md or source files could influence the agent's analysis, potentially leading it to misreport safety findings or bypass governance requirements.
  • Ingestion points: scripts/discover_assets.py recursively reads and extracts content from files within the directory specified by the user.
  • Boundary markers: The SKILL.md instructions explicitly tell the agent to stay within the target directory and avoid reading sensitive files, though no cryptographic or strict isolation boundaries exist for the ingested data itself.
  • Capability inventory: The skill has file_write permissions to the target directory and /tmp/, and shell permissions for its own Python scripts.
  • Sanitization: scripts/discover_assets.py includes a redact_sensitive_text function that uses regular expressions to mask potential API keys and tokens before they are processed by the agent. Additionally, scripts/render_card.py performs schema validation on the generated context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 12:57 AM
Security Audit — agent-trust-hub — skill-card-generator