skill-creation-walkthrough

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were identified during the analysis of this skill.
  • [PROMPT_INJECTION]: The skill uses instructional language to guide the user in skill creation but does not attempt to bypass safety filters, override system instructions, or extract sensitive model information.
  • [DATA_EXFILTRATION]: No network operations, credential harvesting, or sensitive file access patterns were detected. The skill operates entirely within the context of generating documentation and guidance.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote scripts or binaries. The skill consists exclusively of markdown documentation and templates.
  • [COMMAND_EXECUTION]: The skill does not invoke shell commands, use dynamic context injection (!command), or perform any administrative operations on the host system.
  • [OBFUSCATION]: No encoded content, hidden characters, or steganographic techniques were found. All instructions and references are in plain text markdown.
  • [INDIRECT_PROMPT_INJECTION]: While the skill assists users in processing their own workflows and task descriptions to create skills, it lacks the dangerous capabilities (like file system writes or network access) required to execute an indirect prompt injection attack. It acts purely as a design and writing assistant.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 04:48 PM
Security Audit — agent-trust-hub — skill-creation-walkthrough