skillsmp-skill-factory
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill demonstrates an indirect prompt injection surface by ingesting external data to generate instructions.
- Ingestion points: Skill specifications and patterns are fetched from the external SkillsMP API (skillsmp.com).
- Boundary markers: No clear delimiters or instructions are present to ensure the agent treats retrieved data as untrusted.
- Capability inventory: The skill generates and exports new skill specifications and complex orchestration pipelines based on the retrieved data.
- Sanitization: There is no evidence of sanitization or filtering applied to the external data before it is interpolated into the generation logic.
- [DATA_EXFILTRATION]: The skill performs network operations to search and retrieve data from skillsmp.com. While consistent with its stated purpose, the domain is not among the default whitelisted services.
Audit Metadata