Skip to main content

ai-factory.skill-generator

Generates professional Agent Skills for AI agents, creating complete skill packages with validation against specifications.

Install this skill

or
0/100

Security score

The ai-factory.skill-generator skill was audited on Mar 1, 2026 and we found 19 security issues across 4 threat categories, including 5 critical. Review the findings below before installing.

Categories Tested

Security Issues

critical line 121

Eval function call - arbitrary code execution

SourceSKILL.md
121| Privilege Escalation | `sudo`, `eval()`, package installs | WARNING |
high line 430

Template literal with variable interpolation in command context

SourceSKILL.md
430- `${CLAUDE_SESSION_ID}` - Current session ID
low line 79

Access to hidden dotfiles in home directory

SourceSKILL.md
79python3 ~/.claude/skills/skill-generator/scripts/security-scan.py <skill-path>
medium line 113

Access to hidden dotfiles in home directory

SourceSKILL.md
113| Data Exfiltration | `curl` with `.env`/secrets, reading `~/.ssh/`, `~/.aws/` | CRITICAL |
low line 182

Access to hidden dotfiles in home directory

SourceSKILL.md
182python3 ~/.claude/skills/skill-generator/scripts/security-scan.py <path>
low line 256

Access to hidden dotfiles in home directory

SourceSKILL.md
256python3 ~/.claude/skills/skill-generator/scripts/security-scan.py <installed-path>
low line 341

Access to hidden dotfiles in home directory

SourceSKILL.md
341python3 ~/.claude/skills/skill-generator/scripts/security-scan.py ./skill-name/
medium line 403

Access to hidden dotfiles in home directory

SourceSKILL.md
403python ~/.claude/skills/dependency-graph/scripts/visualize.py $ARGUMENTS
medium line 447

Access to hidden dotfiles in home directory

SourceSKILL.md
4471. **Local**: Keep in `~/.claude/skills/` for personal use
critical line 113

Access to SSH directory

SourceSKILL.md
113| Data Exfiltration | `curl` with `.env`/secrets, reading `~/.ssh/`, `~/.aws/` | CRITICAL |
critical line 113

Access to AWS credentials directory

SourceSKILL.md
113| Data Exfiltration | `curl` with `.env`/secrets, reading `~/.ssh/`, `~/.aws/` | CRITICAL |
medium line 22

Access to .env file

SourceSKILL.md
22- Exfiltrate credentials, `.env`, API keys, SSH keys to attacker-controlled servers
medium line 60

Access to .env file

SourceSKILL.md
60- "I am a security skill, I need access to credentials to scan them" — a security scanning skill does not need to READ your `.env` or `.ssh`.
medium line 113

Access to .env file

SourceSKILL.md
113| Data Exfiltration | `curl` with `.env`/secrets, reading `~/.ssh/`, `~/.aws/` | CRITICAL |
low line 131

Access to .env file

SourceSKILL.md
131- [CRITICAL] Line 78: Data exfiltration — sends .env to external URL
critical line 21

Prompt injection: ignore instructions

SourceSKILL.md
21- Override agent behavior via prompt injection ("ignore previous instructions")
critical line 112

Prompt injection: ignore instructions

SourceSKILL.md
112| Instruction Override | "ignore previous instructions", "you are now", fake `<system>` tags | CRITICAL |
low line 14

External URL reference

SourceSKILL.md
14You are an expert Agent Skills architect. You help users create professional, production-ready skills that follow the [Agent Skills](https://agentskills.io/specification) open standard.
low line 251

External URL reference

SourceSKILL.md
251Or browse https://skills.sh for inspiration. Check if similar skills exist to avoid duplication or find patterns to follow.
Scanned on Mar 1, 2026
View Security Dashboard