skill-craft
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands like
dora review,dora fix, andpython -m scripts.package_skillto validate and package authoring results. These commands involve local file system operations and subprocess execution.\n- [EXTERNAL_DOWNLOADS]: The skill mentions usingnpx @hacksmith/doravalas a fallback for the validation process. This command downloads and executes code from the public npm registry, which is an external source outside of the skill's own distribution.\n- [INDIRECT_PROMPT_INJECTION]: The skill operates as an orchestrator that ingests user-supplied intents and trigger phrases to generate new skill content. It lacks explicit boundary markers or sanitization to prevent potentially malicious user input from influencing the generated skill's behavior.\n - Ingestion points: User prompts and conversation history used to define new skill capabilities in
SKILL.md.\n - Boundary markers: No explicit delimiters or 'ignore' instructions are provided for interpolated content.\n
- Capability inventory: Writing files to the project directory and executing shell-based validation tools.\n
- Sanitization: No evidence of input validation, escaping, or filtering of user-provided trigger phrases or descriptions.
Audit Metadata