skill-registry
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
jqfor querying and updating theassets/registry.jsonfile andmvfor managing temporary files during updates. These are standard system operations for local data management.\n- [PROMPT_INJECTION]: Indirect prompt injection surface detected (Category 8). Ingestion points:assets/registry.jsonand externalSKILL.mdfiles processed by the skill. Boundary markers: Absent. Capability inventory:jqexecution and local file writing. Sanitization: Absent. The risk is low as operations are confined to the local development environment and serve the primary purpose of skill management.
Audit Metadata