skill-security-auditor
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The
SKILL.mdandscripts/prompt_injection_scanner.pyfiles contain numerous prompt injection strings such as 'ignore all previous instructions' and 'disregard all prior instructions'. These are used exclusively as regex patterns for the auditing engine to detect attacks in target skills and within the 'Manual Audit Checklist' documentation. They are not interpreted as instructions for the agent's behavior. - [COMMAND_EXECUTION]: The skill includes documentation and regex patterns relating to dangerous command execution (e.g.,
os.system,subprocess.call(shell=True)). These are part of the scanner's signature database used to find vulnerabilities in other code. The scanner scripts themselves do not execute these commands. - [DATA_EXFILTRATION]: The skill documentation includes examples of data exfiltration patterns (e.g.,
requests.postto an external collector) for detection purposes. The provided auditor scripts do not perform any outbound network requests. - [CREDENTIALS_UNSAFE]: The code scanner logic includes search patterns for sensitive file paths like
~/.sshand~/.aws. These are used to identify if a scanned skill is attempting to harvest credentials; the auditor skill itself does not access these sensitive paths.
Audit Metadata