add-new-opc-skill
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute multiple local shell commands and Python scripts to automate the creation of new skill assets.
- Evidence includes:
python3 skills/nanobanana/scripts/batch_generate.py,python3 skills/logo-creator/scripts/crop_logo.py,python3 skills/logo-creator/scripts/vectorize.py, and variousgitandghCLI commands. - It also references
npx skills add, which utilizes the Node.js package executor to manage skill installations. - [INDIRECT_PROMPT_INJECTION]: The skill relies on user-provided placeholders such as
<skill-name>,<description>, and<subject>which are directly interpolated into shell commands and file content. - Ingestion points: Placeholders in
SKILL.mdare intended to be replaced with user-supplied data. - Boundary markers: No explicit boundary markers or sanitization instructions are present to prevent command injection (e.g., if a user provides a skill name like
my-skill; rm -rf /). - Capability inventory: The skill has access to the file system (via
cp,git add), script execution (python3), and network operations via external CLI tools (gh pr create). - Sanitization: No sanitization or validation logic is defined for the input placeholders.
Audit Metadata