skill-router
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes metadata (names, descriptions, and tags) from external files like
stdlib/catalog/skill-catalog.json. This presents a surface for indirect prompt injection where instructions embedded in other skills' metadata could theoretically influence the agent's behavior during the discovery process. - Ingestion points:
SKILL.md(bash commands querying local catalog files). - Boundary markers: Absent.
- Capability inventory:
Read,Grep,Glob,Bash(limited to python and jq binaries). - Sanitization: Absent.
- [COMMAND_EXECUTION]: The skill uses bash commands including
jq,find, andgrepto search the local filesystem (stdlibdirectory). These commands are restricted to read-only discovery tasks and do not interact with sensitive system files or external networks. - [SAFE]: No evidence of credential exposure, data exfiltration, obfuscation, or persistence mechanisms was found. The skill's operations are consistent with its stated purpose as a meta-tool for library management.
Audit Metadata