write-a-skill
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely instructional, providing guidelines for the creation, structure, and documentation of new agent skills. It does not include any active scripts or automated tool invocations.
- [SAFE]: Security is treated as a core component of the skill development process. The 'skill-contract.md' reference specifically instructs developers to define 'Red lines' which require stopping for explicit confirmation when security risks or high-ambiguity tasks are encountered.
- [SAFE]: No evidence of prompt injection, data exfiltration, or obfuscation was found in either the primary skill definition or its supporting documentation.
- [SAFE]: References to external project files (e.g., package manifests, README.md) are used for legitimate project discovery and do not involve unauthorized access to sensitive user data.
Audit Metadata