add-new-opc-skill

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute multiple local shell commands and Python scripts to automate the creation of new skill assets.
  • Evidence includes: python3 skills/nanobanana/scripts/batch_generate.py, python3 skills/logo-creator/scripts/crop_logo.py, python3 skills/logo-creator/scripts/vectorize.py, and various git and gh CLI commands.
  • It also references npx skills add, which utilizes the Node.js package executor to manage skill installations.
  • [INDIRECT_PROMPT_INJECTION]: The skill relies on user-provided placeholders such as <skill-name>, <description>, and <subject> which are directly interpolated into shell commands and file content.
  • Ingestion points: Placeholders in SKILL.md are intended to be replaced with user-supplied data.
  • Boundary markers: No explicit boundary markers or sanitization instructions are present to prevent command injection (e.g., if a user provides a skill name like my-skill; rm -rf /).
  • Capability inventory: The skill has access to the file system (via cp, git add), script execution (python3), and network operations via external CLI tools (gh pr create).
  • Sanitization: No sanitization or validation logic is defined for the input placeholders.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 03:59 PM
Security Audit — agent-trust-hub — add-new-opc-skill