skills/a-canary/arc-skills/hillclimb/Gen Agent Trust Hub

hillclimb

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository's CHOICES.md file to determine the scope, metric, and gate for its automated improvement cycles.
  • Ingestion points: The skill parses parameters from CHOICES.md in Step 1 of the loop.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands within the parsed parameters are mentioned.
  • Capability inventory: The skill possesses the ability to propose Pull Requests (Step 3), execute arbitrary code modifications via the /task skill (Step 5), and write data to the objective_metrics file (Step 2 and 6).
  • Sanitization: There is no evidence of sanitization or validation of the input parameters parsed from the repository files before they are used to drive the improvement loop.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:52 PM
Security Audit — agent-trust-hub — hillclimb