skill-optimizer
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill encourages users to clone and execute code from an external third-party repository ("https://github.com/yusufkaraaslan/Skill_Seekers") for documentation scraping purposes, as seen in "scripts/scrape_documentation_helper.py" and "references/documentation-scraping.md".
- [COMMAND_EXECUTION]: Several scripts utilize the "subprocess" module to interact with the system. "scripts/run_eval.py" executes the "claude" CLI to perform evaluations, and "eval-viewer/generate_review.py" uses "lsof" and "os.kill" for managing its local web server.
- [INDIRECT_PROMPT_INJECTION]: The evaluation framework is designed to ingest and process untrusted data from external evaluation sets ("evals.json") and the resulting agent transcripts, which could contain malicious instructions. Evidence: 1. Ingestion points: "evals/evals.json" and agent output transcripts. 2. Boundary markers: Absent in prompt interpolation. 3. Capability inventory: "subprocess" and file system access. 4. Sanitization: Arguments are passed to CLI as a list rather than a shell string.
- [DYNAMIC_CONTEXT_INJECTION]: The instructions in "SKILL.md" and "references/frontmatter-reference.md" provide extensive documentation and examples on implementing the platform's dynamic context syntax, which executes shell commands before skill instructions are processed by the AI.
Audit Metadata