template-creator
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell commands like
grep,head, andwcfor validating the integrity of created templates and ensuring that post-creation integration steps, such as catalog and README updates, are correctly performed. - [EXTERNAL_DOWNLOADS]: The skill requires the agent to perform research using external platforms like Exa and arXiv to ensure that new templates align with industry standards and academic best practices. These references are documented neutrally as they target well-known research services.
- [INDIRECT_PROMPT_INJECTION]: The skill manages the ingestion of user-provided requirements to generate templates, which constitutes a potential injection surface. However, the skill implements a comprehensive defense strategy:
- Ingestion points: Template requirements are gathered during the requirement analysis phase (SKILL.md Step 1).
- Boundary markers: The system uses a strict double-brace placeholder format (e.g.,
{{PLACEHOLDER}}) to isolate substituted values. - Capability inventory: The skill uses
Bashfor verification andfs.writeFileSync(viascripts/main.cjs) for artifact creation. - Sanitization: Mandatory compliance with SEC-TC-001 requires all substitution values in spawn prompts to be sanitized using
sanitizeSubstitutionValue()to mitigate injection risks. - [SAFE]: The skill enforces multiple security standards (SEC-TC-007, SEC-TMPL-006, SEC-TC-003) that explicitly forbid the inclusion of secrets, absolute paths, and Windows reserved names, ensuring that the generated templates are safe for framework-wide use.
Audit Metadata