skill-improver

Pass

Audited by Gen Agent Trust Hub on Mar 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references a prerequisite 'plugin-dev' plugin from the Trail of Bits repository, which is a recognized security firm.
  • [PROMPT_INJECTION]: The skill architecture facilitates indirect prompt injection by processing external skill files.
  • Ingestion points: The agent is instructed to read and parse the content of 'SKILL.md' files provided at user-specified absolute paths.
  • Boundary markers: The methodology does not specify the use of delimiters or instructions to ignore potential commands embedded within the target skill files.
  • Capability inventory: The agent is prompted to perform file modifications ('Fix' stage) and execute tools ('Review' stage) based on the content of the ingested files.
  • Sanitization: No input validation or sanitization of the target skill content is performed before the agent acts upon the data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 7, 2026, 03:42 PM