manage-skills
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use various shell commands for filesystem manipulation.
- Evidence includes:
mkdir -p,cat >,mv,cp -r,rm -rf,find, andgrep. - The commands are used to manage directories and files associated with AI agent tools (e.g.,
~/.cursor/skills/,~/.windsurf/rules/). - [DATA_EXPOSURE]: The skill provides the agent with access to sensitive configuration and instruction files for multiple AI developer tools.
- It targets specific paths such as
~/.aider.conf.yml,~/.github/copilot-instructions.md,~/.codex/AGENTS.md, and~/augment-guidelines.md. - These files define agent behavior and rules, and in some cases (like Aider), could contain sensitive operational metadata.
- [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by design.
- Ingestion points: The agent is instructed to read contents of
SKILL.mdand other configuration files usingcatandgrepacross numerous tool directories. - Boundary markers: There are no instructions or boundary markers provided to ensure the agent disregards instructions contained within the files it is "managing."
- Capability inventory: The skill possesses significant file system capabilities, including writing new files (
cat >), moving files (mv), and deleting directories (rm -rf). - Sanitization: There is no evidence of sanitization or validation of the content being read from or written to these configuration files.
Audit Metadata