skillify
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests the current conversation history to generate reusable instructions. This creates a risk where malicious input previously provided in the session (e.g., from an untrusted file or website read earlier) could be incorporated into the new skill's logic.
- Ingestion points: Reads and analyzes the active session history within
SKILL.mdStep 1. - Boundary markers: Absent. The agent is instructed to analyze the entire session context without explicit isolation for untrusted segments.
- Capability inventory: The skill has
WriteandBash(mkdir:*)permissions to persist generated content to~/.claude/skills/or project directories. - Sanitization: The skill implements a mitigation via
AskUserQuestionin Step 4, requiring the user to review and confirm the generated content before it is saved to disk. - [COMMAND_EXECUTION]: The skill uses the
Bashtool restricted to themkdircommand to create directories for storing new skill files. This is a functional requirement but represents a capability that is used to persist newly generated (and potentially injected) logic.
Audit Metadata