skillsmp-skill-factory

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill demonstrates an indirect prompt injection surface by ingesting external data to generate instructions.
  • Ingestion points: Skill specifications and patterns are fetched from the external SkillsMP API (skillsmp.com).
  • Boundary markers: No clear delimiters or instructions are present to ensure the agent treats retrieved data as untrusted.
  • Capability inventory: The skill generates and exports new skill specifications and complex orchestration pipelines based on the retrieved data.
  • Sanitization: There is no evidence of sanitization or filtering applied to the external data before it is interpolated into the generation logic.
  • [DATA_EXFILTRATION]: The skill performs network operations to search and retrieve data from skillsmp.com. While consistent with its stated purpose, the domain is not among the default whitelisted services.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 02:18 PM
Security Audit — agent-trust-hub — skillsmp-skill-factory