skill-router

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes metadata (names, descriptions, and tags) from external files like stdlib/catalog/skill-catalog.json. This presents a surface for indirect prompt injection where instructions embedded in other skills' metadata could theoretically influence the agent's behavior during the discovery process.
  • Ingestion points: SKILL.md (bash commands querying local catalog files).
  • Boundary markers: Absent.
  • Capability inventory: Read, Grep, Glob, Bash (limited to python and jq binaries).
  • Sanitization: Absent.
  • [COMMAND_EXECUTION]: The skill uses bash commands including jq, find, and grep to search the local filesystem (stdlib directory). These commands are restricted to read-only discovery tasks and do not interact with sensitive system files or external networks.
  • [SAFE]: No evidence of credential exposure, data exfiltration, obfuscation, or persistence mechanisms was found. The skill's operations are consistent with its stated purpose as a meta-tool for library management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — skill-router