skills/orziz/aiskills/skill-sync/Gen Agent Trust Hub

skill-sync

Warn

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local JavaScript file located at scripts/skill-sync.js. This script is the primary execution logic for the synchronization process, granting it control over file generation and platform-specific updates.
  • [DATA_EXFILTRATION]: The skill performs extensive read and write operations across the repository, specifically targeting sensitive platform configuration directories such as .claude/commands/, .github/skills/, and .trae/rules/. This broad file system access allows for the modification of agent behavior and repository metadata.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection. It ingests content from skills/<skill-name>/SKILL.md (untrusted source) and writes it directly into command definitions for various platforms without sanitization or boundary markers. * Ingestion points: skills/<skill-name>/SKILL.md and associated resource directories. * Boundary markers: Absent; the skill explicitly mandates direct copying of source text without modification. * Capability inventory: Execution of scripts/skill-sync.js and broad write access to agent/platform configuration directories. * Sanitization: Absent; no validation or escaping of the source content is performed before propagation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 12, 2026, 05:09 AM