ai-request-skill
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Employs shell commands such as git and gh to manage branches, commits, and automate the creation of pull requests and issues on GitHub.
- [EXTERNAL_DOWNLOADS]: References and optionally installs the skill-creator utility from the official Anthropic skills repository, which is a trusted source.
- [PROMPT_INJECTION]: Ingests user input to generate skill content and GitHub descriptions, creating a surface for indirect prompt injection. Ingestion point: $ARGUMENTS in SKILL.md. Capability inventory: git, gh, npx, cp, cat. Boundary markers: None. Sanitization: None.
Audit Metadata