manage-local-skills

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides utility scripts like inspect-source.mjs and install-skill.mjs to perform file system operations such as directory analysis, copying files, and creating symlinks.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface as it processes external SKILL.md files in scripts/validate-skill.mjs. Ingestion points: scripts/validate-skill.mjs reads SKILL.md content via fs.readFileSync. Boundary markers: Operating rules require user confirmation for file writes and batch operations. Capability inventory: scripts/lib/install-model.mjs can perform recursive directory deletion, directory creation, file copying, and symlinking. Sanitization: scripts/lib/path-safety.mjs implements isPathSafe checks and sanitizeSkillName to prevent directory traversal and path manipulation.
  • [SAFE]: Path safety logic in scripts/lib/path-safety.mjs uses normalization and resolution to ensure file operations are confined to authorized agent and project directories.
  • [SAFE]: No network access or remote execution patterns were found, and the skill includes explicit rules against executing unknown scripts during the inspection process.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — manage-local-skills