skill-build
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as its primary purpose is to ingest and analyze untrusted external data (package code, READMEs, tests, and documentation) to generate new agent instructions. Maliciously crafted content within a package being analyzed could potentially influence the agent's behavior or the content of the generated skills.
- Ingestion points: README,
__init__.py, core modules, tests, andpyproject.tomlfiles in target packages. - Boundary markers: No explicit instruction delimiters or warnings to ignore embedded instructions are provided in the workflow.
- Capability inventory: The agent is instructed to read local files, write new markdown files, and execute CLI commands.
- Sanitization: No explicit sanitization or validation of the analyzed content is mentioned before processing.
- [COMMAND_EXECUTION]: The instructions direct the agent to execute several local CLI commands, specifically
skill validate,skill link-skills, andskill list-skills. These are presented as standard utility commands for the skill development lifecycle within the vendor's ecosystem.
Audit Metadata