skill-auditor

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is composed purely of markdown instructions and reference files. It does not include any scripts, binaries, or automated command executions.
  • [PROMPT_INJECTION]: There is a minimal surface for indirect prompt injection (Category 8) because the skill processes untrusted user-provided markdown files for auditing.
  • Ingestion points: The agent is instructed to ask the user to "Paste the SKILL.md or REFERENCE file content" or "provide the file path" in the SKILL.md file.
  • Boundary markers: No specific delimiters (e.g., XML tags or triple backticks) are mandated for the agent to use when interpreting the untrusted content.
  • Capability inventory: The skill lacks any dangerous capabilities such as file writing, shell execution, or network exfiltration, which significantly limits the impact of any potential injection.
  • Sanitization: No explicit sanitization of the provided file content is defined in the instructions.
  • [DATA_EXPOSURE]: The skill requests file paths from the user. While this involves file system access, it is the intended purpose of the auditor and does not target sensitive system directories or credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 03:52 AM
Security Audit — agent-trust-hub — skill-auditor