distill-skill

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is a transformer that converts untrusted security content into structured instructions for other AI agents.
  • Ingestion points: The skill processes raw security content provided by the user, such as bug reports, blog posts, and CTF writeups (defined in SKILL.md).
  • Boundary markers: The instructions lack specific delimiters or instructions to treat the input source as untrusted data, allowing the source content to potentially influence the agent's logic.
  • Capability inventory: The resulting output is a new 'SKILL.md' file, which defines the methodology and behavior for future agent sessions.
  • Sanitization: While the skill mandates anonymization of PII and specific targets, it does not include sanitization or filtering to prevent the source material from injecting malicious instructions into the generated methodology.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:34 PM
Security Audit — agent-trust-hub — distill-skill