yy-create-skill
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional and metadata-driven. It guides the AI agent in generating standard markdown files for skill definitions.
- [COMMAND_EXECUTION]: While the skill documents the syntax for dynamic context injection (e.g., shell commands in frontmatter used by platforms like Claude Code), it does so for educational and comparison purposes within its documentation. The skill itself does not employ these techniques to execute unauthorized commands.
- [DATA_EXFILTRATION]: No network operations (curl, wget, etc.) or external data transmission patterns were detected. The skill operates locally on the file system.
- [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or access to sensitive configuration files (like .ssh or .aws) were found.
- [PROMPT_INJECTION]: The instructions focus on procedural steps for skill creation and do not contain patterns aimed at overriding agent safety guidelines or extracting system prompts.
Audit Metadata