OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Fail4 providerslatest audit Mar 18, 2026
Independent checks from skills.sh's audit partners.
This skill assists in authoring new agent skills by guiding the agent to read existing skill files and execute local validation scripts. It presents a significant Indirect Prompt Injection risk: the agent is instructed to ingest potentially untrusted content from other repository files and then perform file-system operations and code execution. This combination of untrusted data ingestion and high-privilege capabilities allows for malicious instructions in other skills to compromise the agent's behavior.
Detected behaviors
No alerts
No issues
4 files scanned · No issues