skill-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill encourages users to clone and execute code from an external third-party repository ("https://github.com/yusufkaraaslan/Skill_Seekers") for documentation scraping purposes, as seen in "scripts/scrape_documentation_helper.py" and "references/documentation-scraping.md".
  • [COMMAND_EXECUTION]: Several scripts utilize the "subprocess" module to interact with the system. "scripts/run_eval.py" executes the "claude" CLI to perform evaluations, and "eval-viewer/generate_review.py" uses "lsof" and "os.kill" for managing its local web server.
  • [INDIRECT_PROMPT_INJECTION]: The evaluation framework is designed to ingest and process untrusted data from external evaluation sets ("evals.json") and the resulting agent transcripts, which could contain malicious instructions. Evidence: 1. Ingestion points: "evals/evals.json" and agent output transcripts. 2. Boundary markers: Absent in prompt interpolation. 3. Capability inventory: "subprocess" and file system access. 4. Sanitization: Arguments are passed to CLI as a list rather than a shell string.
  • [DYNAMIC_CONTEXT_INJECTION]: The instructions in "SKILL.md" and "references/frontmatter-reference.md" provide extensive documentation and examples on implementing the platform's dynamic context syntax, which executes shell commands before skill instructions are processed by the AI.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 02:50 AM
Security Audit — agent-trust-hub — skill-optimizer