skill-map
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
ai-skillet mapcommand with arguments to find skill installations, duplicates, and cross-references across the local filesystem. This is a non-standard utility performing broad discovery operations.\n- [EXTERNAL_DOWNLOADS]: The skill specifies a compatibility requirement forai-skilletversion 0.1.0 or newer to be present on the systemPATH. This is a non-standard external dependency that is not managed within the skill itself.\n- [INDIRECT_PROMPT_INJECTION]: The skill scans local files and repository portfolios to extract skill definitions and reference snippets. This represents an attack surface where malicious instructions embedded in the scanned files could be processed by the agent.\n - Ingestion points: Broad machine scans including authored sources and project references in the local filesystem (SKILL.md, references/ignore-policy.md).\n
- Boundary markers: Absent. There are no instructions provided to delimit untrusted file content or to warn the agent to ignore instructions found within the data.\n
- Capability inventory: Shell command execution and broad local file discovery and reading.\n
- Sanitization: Absent. The instructions focus on maintaining output format validity (JSON/DOT/Text) rather than sanitizing the content of the identified skills or extracted snippets.
Audit Metadata