create-skill
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest user input through a conversational interview and write those inputs into new instruction files (SKILL.md).
- Ingestion points: User responses gathered during the three-question interview described in Step 1 of
SKILL.md. - Boundary markers: No specific delimiters are mandated for user input, though the skill provides structured sections (Steps, Gotchas, etc.) to house the information.
- Capability inventory: The skill is intended to perform file system write operations to
~/.claude/skills/or.claude/skills/as specified in Step 2 and Step 6 ofSKILL.md. - Sanitization: The instructions focus on content quality and triggering accuracy rather than input sanitization, which is expected for a developer-oriented creation tool.
- Assessment: This represents the core functional surface of a meta-skill and does not pose a threat in this context.
Audit Metadata