skill-creator
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references an external documentation server at 'https://agentskills.io/mcp' and provides specific instructions for the agent to configure it as an MCP server across different IDEs and CLI environments.
- [COMMAND_EXECUTION]: The skill provides instructions and code templates for executing local scripts using several runtimes including 'uv', 'deno', 'bun', and 'ruby'. It also includes commands intended to modify local configuration files for agent frameworks.
- [PROMPT_INJECTION]: The skill defines a workflow where the agent ingests and synthesizes content from untrusted artifacts like git patches, code review comments, and incident reports. This process lacks explicit boundary markers and sanitization instructions, creating a surface for indirect prompt injection.
Audit Metadata