skill-creator-primer

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONOBFUSCATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes scripts that execute subprocesses for auditing and testing purposes.
  • scripts/hook_report_skill_tokens.py executes the validate_skill.py script to provide real-time token budget feedback.
  • scripts/eval_triggering.py uses subprocess.Popen to drive the claude CLI for testing skill activation triggers in an isolated scratch project.
  • [OBFUSCATION]: The skill includes a validator (scripts/validate_skill.py) specifically designed to detect hidden or invisible Unicode characters often used in steganographic prompt injections.
  • tests/test_validate_skill.py contains test fixtures with invisible characters (such as U+00A0, U+200B, and U+FEFF) used exclusively to verify the efficacy of the detector.
  • [INDIRECT_PROMPT_INJECTION]: As a meta-skill for skill creation, it processes external data from other skill files for linting and analysis.
  • The skill provides an evidence-based framework for identifying and mitigating injection vulnerabilities in the skills it audits.
  • It implements boundary markers and sanitization guidance for agent instructions.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill documentation describes and utilizes platform-specific execution features for legitimate developer workflows.
  • A PostToolUse hook is configured in the frontmatter to automatically trigger token reporting after file edits, facilitating immediate security and performance feedback.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 10:47 AM
Security Audit — agent-trust-hub — skill-creator-primer