create-skill

Warn

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill promotes the execution of unversioned remote code via the npx command (@hacksmith/doraval), which downloads and runs packages from the NPM registry.
  • [EXTERNAL_DOWNLOADS]: The skill instructions depend on fetching the @hacksmith/doraval package from an external registry during the validation phase.
  • [COMMAND_EXECUTION]: The skill uses local Python scripts (scripts.package_skill, run_loop.py, eval-viewer/generate_review.py) and shell commands for packaging and reviewing skills.
  • [PROMPT_INJECTION]: The skill processes untrusted user requests to generate agent instructions, creating a surface for indirect prompt injection. Ingestion points: Capture phase in SKILL.md. Boundary markers: None mentioned. Capability inventory: npx, python subprocesses, and local file system operations. Sanitization: No sanitization logic provided for user-supplied input.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 21, 2026, 06:58 AM
Security Audit — agent-trust-hub — create-skill