skill-improver
Pass
Audited by Gen Agent Trust Hub on Mar 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references a prerequisite 'plugin-dev' plugin from the Trail of Bits repository, which is a recognized security firm.
- [PROMPT_INJECTION]: The skill architecture facilitates indirect prompt injection by processing external skill files.
- Ingestion points: The agent is instructed to read and parse the content of 'SKILL.md' files provided at user-specified absolute paths.
- Boundary markers: The methodology does not specify the use of delimiters or instructions to ignore potential commands embedded within the target skill files.
- Capability inventory: The agent is prompted to perform file modifications ('Fix' stage) and execute tools ('Review' stage) based on the content of the ingested files.
- Sanitization: No input validation or sanitization of the target skill content is performed before the agent acts upon the data.
Audit Metadata