skill-registry

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses jq for querying and updating the assets/registry.json file and mv for managing temporary files during updates. These are standard system operations for local data management.\n- [PROMPT_INJECTION]: Indirect prompt injection surface detected (Category 8). Ingestion points: assets/registry.json and external SKILL.md files processed by the skill. Boundary markers: Absent. Capability inventory: jq execution and local file writing. Sanitization: Absent. The risk is low as operations are confined to the local development environment and serve the primary purpose of skill management.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 06:24 AM