curate-skills
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill's behavior is consistent with its stated purpose of auditing and normalizing repository content.
- [PROMPT_INJECTION]: As a meta-skill that processes other skill files, it contains an inherent surface for indirect prompt injection. This is a characteristic of auditing tools rather than a vulnerability, but it remains a relevant surface for data ingestion.
- Ingestion points:
agent.yaml,README.md, andSKILL.mdfiles within the providedskills_directory(SKILL.md). - Boundary markers: No explicit delimiter or instructions to ignore embedded commands are mentioned in the reading logic.
- Capability inventory: File system read and write access for updating metadata and generating the
ASQM_AUDIT.mdreport. - Sanitization: No specific filtering or validation mechanisms for the content being processed are described.
Audit Metadata