umbraco-skill-evaluator

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process transcripts and output files generated by other agent skills during evaluation. This creates a surface where a malicious skill being tested could include instructions intended to influence the grading subagent or the user via the HTML viewer.
  • Ingestion points: eval-viewer/generate_review.py reads file contents from outputs/ subdirectories; agents/grader.md instructs the grader subagent to read the execution transcript and all files in the outputs_dir.
  • Boundary markers: The grader instructions in agents/grader.md lack explicit delimiters or instructions to ignore embedded commands within the files being evaluated.
  • Capability inventory: The skill can spawn subagents (Haiku), perform recursive file system deletions, and run a local HTTP server.
  • Sanitization: While the HTML viewer in eval-viewer/viewer.html uses escaping for some metadata, it renders file contents in <pre> tags and uses the SheetJS library to render spreadsheet data, which could be exploited if the inputs contain malicious content.
  • [COMMAND_EXECUTION]: The skill uses shell commands and Python system calls to manage its execution environment and workspace.
  • Evidence: eval-viewer/generate_review.py uses subprocess.run to execute lsof for port discovery and os.kill to terminate processes occupying the server port.
  • Evidence: scripts/cleanup_workspace.py performs recursive directory removal using shutil.rmtree and file deletion via os.unlink to clean up the workspace.
  • Evidence: SKILL.md instructs the agent to use nohup for background process execution and kill for process termination.
  • [EXTERNAL_DOWNLOADS]: The skill's HTML viewer references external resources from well-known providers.
  • Evidence: eval-viewer/viewer.html fetches the SheetJS library from https://cdn.sheetjs.com/xlsx-0.20.3/package/dist/xlsx.full.min.js to enable spreadsheet rendering.
  • Evidence: eval-viewer/viewer.html loads typography assets from Google Fonts at https://fonts.googleapis.com and https://fonts.gstatic.com.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 05:19 PM