skill-author
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's core functionality involves managing and organizing files within the
skills/directory. It requires read and write access to these paths, which is entirely consistent with its stated purpose as a 'skill-author' assistant. - [SAFE]: No suspicious network activity, external data exfiltration, or obfuscation techniques (like Base64 or hidden characters) were identified in the instructions.
- [SAFE]: The skill includes robust safety guardrails, such as requiring the agent to lock target paths and seek explicit user confirmation before overwriting, renaming, or creating new content.
- [SAFE]: While the skill processes user-provided content to generate skill files, which is an indirect prompt injection surface, it mitigates this risk by utilizing a structured skeleton and manual confirmation checkpoints.
Audit Metadata