skill-creator-expert

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill serves as a documentation and template provider for skill development. It does not contain any executable scripts, remote downloads, or obfuscated content.
  • [INDIRECT_PROMPT_INJECTION]: As a tool designed to generate and process code/documentation, it has an inherent attack surface for indirect injection. However, the skill explicitly includes a validation engine in its framework intended to sanitize and check generated content for security issues like hardcoded credentials and dangerous tool usage, mitigating the risk.
  • [COMMAND_EXECUTION]: The skill's frontmatter allows the Execute tool, which is appropriate for its stated purpose of validating and testing newly created skills. No suspicious or hardcoded commands were found in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:42 PM
Security Audit — agent-trust-hub — skill-creator-expert