template-creator

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell commands like grep, head, and wc for validating the integrity of created templates and ensuring that post-creation integration steps, such as catalog and README updates, are correctly performed.
  • [EXTERNAL_DOWNLOADS]: The skill requires the agent to perform research using external platforms like Exa and arXiv to ensure that new templates align with industry standards and academic best practices. These references are documented neutrally as they target well-known research services.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages the ingestion of user-provided requirements to generate templates, which constitutes a potential injection surface. However, the skill implements a comprehensive defense strategy:
  • Ingestion points: Template requirements are gathered during the requirement analysis phase (SKILL.md Step 1).
  • Boundary markers: The system uses a strict double-brace placeholder format (e.g., {{PLACEHOLDER}}) to isolate substituted values.
  • Capability inventory: The skill uses Bash for verification and fs.writeFileSync (via scripts/main.cjs) for artifact creation.
  • Sanitization: Mandatory compliance with SEC-TC-001 requires all substitution values in spawn prompts to be sanitized using sanitizeSubstitutionValue() to mitigate injection risks.
  • [SAFE]: The skill enforces multiple security standards (SEC-TC-007, SEC-TMPL-006, SEC-TC-003) that explicitly forbid the inclusion of secrets, absolute paths, and Windows reserved names, ensuring that the generated templates are safe for framework-wide use.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:33 PM
Security Audit — agent-trust-hub — template-creator