self-improvement
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes several automation scripts (Python and Shell) for managing the learning store. Specifically,
scripts/run_in_wsl.ps1serves as a bridge for Windows users to execute the project's shell scripts via WSL, involving the construction and execution of shell command strings. - [PROMPT_INJECTION]: The skill facilitates the modification of core agent instruction files (e.g.,
AGENTS.md,CLAUDE.md,.github/copilot-instructions.md) by 'promoting' captured learnings into these files. This creates an indirect prompt injection surface if malicious or misleading instructions are logged and later promoted. - Ingestion points: Data is ingested from the
.learnings/directory, specifically fromLEARNINGS.md,ERRORS.md, andFEATURE_REQUESTS.md(e.g., inscripts/promote_learning.py). - Boundary markers: While the skill uses specific header sections (e.g., 'Self-Improvement Promotions') to organize promoted rules, it does not implement programmatic wrappers or instructions for the agent to ignore potentially malicious embedded content within those rules.
- Capability inventory: The skill has the capability to write to local instruction files via
scripts/promote_learning.pyand execute various shell commands through the included helper scripts. - Sanitization: No programmatic sanitization or validation of the learning content is performed before it is distilled and appended to the project's primary instruction files.
Audit Metadata