skills/simota/agent-skills/sigil/Gen Agent Trust Hub

sigil

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository being analyzed, including manifest files, source code, and AI-specific rule files (e.g., CLAUDE.md, .cursorrules). This data is used to generate executable skill instructions and configurations, potentially allowing a malicious repository to manipulate the output.
  • Ingestion points: Project manifest files (package.json, go.mod, etc.), source code directories, and various AI rule files as defined in the reference/cross-tool-rules-landscape.md file.
  • Boundary markers: The skill employs a "path + selective excerpt strategy" during scanning to minimize ingestion of unnecessary data.
  • Capability inventory: The skill utilizes Bash, Read, Glob, and Grep tools and has the capability to write to project-specific skill directories (.claude/skills/).
  • Sanitization: Instructions explicitly warn against including XML angle brackets in YAML frontmatter to prevent prompt-injection hazards.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill documents and supports the generation of skills utilizing the !command`` syntax for dynamic context injection. This feature allows shell command output to be injected into the agent's prompt at load time. The skill provides benign examples (e.g., git branch) and advises using only trusted commands.
  • [COMMAND_EXECUTION]: The skill performs project analysis by executing shell commands (e.g., git, cat, jq) via the Bash tool to detect tech stacks, dependencies, and current project state.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — sigil