create-skill

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The instructions direct the agent to execute local utility scripts (scripts/init_skill.py and scripts/package_skill.py) to scaffold new skill directories and validate/package completed skills for distribution.
  • [REMOTE_CODE_EXECUTION]: The workflow involves generating new executable logic (Python or Bash scripts) and explicitly instructs the agent to test these scripts by running them locally. This dynamic execution is a core component of the skill's development-focused purpose.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests user-provided "concrete examples" and requirements to define the logic, instructions, and code for new skills.
  • Ingestion points: SKILL.md (Step 1 and Step 2 of the creation process).
  • Boundary markers: None explicitly defined in the instructions.
  • Capability inventory: File system writes (creating skills) and script execution (testing generated code).
  • Sanitization: Not present; the agent is expected to interpret and implement user requests directly.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 02:07 PM
Security Audit — agent-trust-hub — create-skill