distilling-skills
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: Performs network requests to skills.sh to search for skills. This activity is restricted to discovery and retrieval of metadata related to the skill's primary function.\n- [PROMPT_INJECTION]: Ingests and processes data from external sources, which represents a surface for indirect prompt injection.\n
- Ingestion points: Reads skill metadata and SKILL.md content from skills.sh and GitHub repositories.\n
- Boundary markers: Lacks explicit delimiter-based isolation for external content during the synthesis and integration phase.\n
- Capability inventory: The skill is authorized to modify, create, and organize local skill files and directories.\n
- Sanitization: Includes a mandatory security verification phase that requires the agent to check third-party security audits (e.g., Socket, Snyk) and identify dangerous code patterns (such as piped shell scripts) before processing content.
Audit Metadata