skill-router
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to find, list, and read the metadata (name and description) of every installed skill on the filesystem to decide which one to use. This creates an attack surface where a malicious skill could include instructions in its metadata intended to hijack the routing process or influence the agent's behavior.
- Ingestion points:
SKILL.mdfiles found in tool-specific paths such as.claude/skills/or~/.claude/skills/(Step 1 and Step 2 in SKILL.md). - Boundary markers: Absent. The instructions do not provide delimiters or warnings to the agent to ignore instructions embedded within the metadata it reads.
- Capability inventory: The skill utilizes filesystem discovery (directory listing) and file reading capabilities across the user's home and configuration directories.
- Sanitization: Absent. The skill does not specify any validation, filtering, or escaping of the metadata content before it is processed by the agent's decision-making logic.
Audit Metadata