skill-craft

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands like dora review, dora fix, and python -m scripts.package_skill to validate and package authoring results. These commands involve local file system operations and subprocess execution.\n- [EXTERNAL_DOWNLOADS]: The skill mentions using npx @hacksmith/doraval as a fallback for the validation process. This command downloads and executes code from the public npm registry, which is an external source outside of the skill's own distribution.\n- [INDIRECT_PROMPT_INJECTION]: The skill operates as an orchestrator that ingests user-supplied intents and trigger phrases to generate new skill content. It lacks explicit boundary markers or sanitization to prevent potentially malicious user input from influencing the generated skill's behavior.\n
  • Ingestion points: User prompts and conversation history used to define new skill capabilities in SKILL.md.\n
  • Boundary markers: No explicit delimiters or 'ignore' instructions are provided for interpolated content.\n
  • Capability inventory: Writing files to the project directory and executing shell-based validation tools.\n
  • Sanitization: No evidence of input validation, escaping, or filtering of user-provided trigger phrases or descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 08:56 AM
Security Audit — agent-trust-hub — skill-craft