skills/pksorensen/skillz/skill-review/Gen Agent Trust Hub

skill-review

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on executing local shell commands and a bundled audit script to analyze skill structure and file organization. This includes using grep to find skill callers and git for version control operations during skill updates.
  • [PROMPT_INJECTION]: The skill processes the content of other agent skills as data, which is a potential surface for indirect prompt injection. This risk is mitigated by explicit instructions to treat all reviewed skill content as non-authoritative data rather than as guidance for the agent's own behavior.
  • [SAFE]: No malicious patterns such as credential harvesting, obfuscation, or network-based data exfiltration were found. The tool is designed for project maintenance and follows best practices for tool execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 01:22 PM
Security Audit — agent-trust-hub — skill-review