skills/simota/agent-skills/builder/Gen Agent Trust Hub

builder

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for setting up environment-specific tools and recommends several external packages for implementation tasks.
  • For image generation, it instructs the user to install the google-genai Python library via pip.
  • For CLI and TUI development, it provides a matrix of well-known libraries such as ink (Node.js), rich (Python), bubbletea (Go), and ratatui (Rust).
  • These recommendations target official registries (PyPI, NPM, Crates.io) and established open-source projects, which is consistent with the skill's primary purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied requirements to generate prompts for external image-generation models (Google Gemini).
  • This creates an attack surface where a user could potentially supply instructions intended to bypass the image model's safety filters.
  • The skill mitigates this by including a dedicated image-policy recipe and reference/image-generation-content-safety.md, which defines a five-layer policy stack (pre-prompt filtering, post-generation classifiers, and persona refusals) to ensure compliance with content guidelines.
  • [COMMAND_EXECUTION]: The skill is designed to drive production-grade code implementation, including the generation of Python scripts, CLI tools, and build configurations.
  • It includes detailed guidance on authoring shell commands, handling exit codes, and cross-platform signal management.
  • The skill emphasizes safety practices like using timingSafeEqual for webhook verification and preventing ReDoS (Regular Expression Denial of Service) by auditing regex patterns against untrusted input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:50 PM
Security Audit — agent-trust-hub — builder