manage-skills

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use various shell commands for filesystem manipulation.
  • Evidence includes: mkdir -p, cat >, mv, cp -r, rm -rf, find, and grep.
  • The commands are used to manage directories and files associated with AI agent tools (e.g., ~/.cursor/skills/, ~/.windsurf/rules/).
  • [DATA_EXPOSURE]: The skill provides the agent with access to sensitive configuration and instruction files for multiple AI developer tools.
  • It targets specific paths such as ~/.aider.conf.yml, ~/.github/copilot-instructions.md, ~/.codex/AGENTS.md, and ~/augment-guidelines.md.
  • These files define agent behavior and rules, and in some cases (like Aider), could contain sensitive operational metadata.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by design.
  • Ingestion points: The agent is instructed to read contents of SKILL.md and other configuration files using cat and grep across numerous tool directories.
  • Boundary markers: There are no instructions or boundary markers provided to ensure the agent disregards instructions contained within the files it is "managing."
  • Capability inventory: The skill possesses significant file system capabilities, including writing new files (cat >), moving files (mv), and deleting directories (rm -rf).
  • Sanitization: There is no evidence of sanitization or validation of the content being read from or written to these configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:49 PM
Security Audit — agent-trust-hub — manage-skills