agents-skills

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The test scripts in the scripts/ directory (test_audit_skill_metadata.py, test_build_skill_graph.py, and test_validate_skill.py) use subprocess.run to execute the main validator scripts using the current Python interpreter (sys.executable). This is a benign and standard practice for internal regression testing.
  • [EXTERNAL_DOWNLOADS]: The scripts/validate_skill.py utility uses urllib.request to perform network checks on external URLs defined in data/sources.json. This functionality is intended for link validation and is only triggered when the --check-urls command-line flag is explicitly provided.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves parsing and analyzing other skill bundles (including SKILL.md frontmatter and openai.yaml files). While this processes external data, the analysis is limited to regex-based static checks and does not evaluate or execute the content in a way that would facilitate prompt injection attacks against the host agent.
  • [SAFE]: The data/sources.json file contains a curated list of references to official documentation and community tools from trusted organizations such as Anthropic, Microsoft, OpenAI, and well-known GitHub repositories. These references are documented neutrally and used for technical verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — agents-skills