skillkit-help
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied skill content or file paths in 'Path B: Validate an Existing Skill' for quality checking purposes. While this creates a surface for indirect prompt injection, the skill lacks tool permissions or dangerous operations that could be exploited, and the behavior is central to the skill's primary utility.
- Ingestion points:
SKILL.md(Path B, Step 2). - Boundary markers: None explicitly defined in the prompt logic to delimit user-provided content.
- Capability inventory: The skill is limited to text analysis and summary output; no subprocess calls, network operations, or file-write capabilities are requested or used by this skill.
- Sanitization: No sanitization is performed as the skill is designed to analyze the raw content for standard patterns.
- [SAFE]: The skill provides standard documentation, templates, and orientation for developers. All referenced knowledge files contain educational material regarding token economics, platform constraints, and architectural best practices. The provided audit commands (e.g., searching for API keys or unsafe function calls) are documented as security best practices for developers to perform manually.
Audit Metadata