agents-md-improver
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests and processes untrusted instruction files from the repository which are specifically designed to influence agent behavior.
- Ingestion points: Reads files named AGENTS.md, CLAUDE.md, .agents.local.md, and .claude.local.md across the repository (SKILL.md).
- Boundary markers: None identified. The skill does not explicitly wrap the content of rules files in delimiters or use instructions to ignore embedded commands during its assessment phase.
- Capability inventory: Executes shell commands for file discovery (find) and possesses file-write capabilities via an editor tool to apply targeted updates (SKILL.md).
- Sanitization: No specific sanitization or escaping of external content is mentioned; however, the workflow mandates a quality report and user approval before any file modifications are applied.
Audit Metadata