self-improve
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection because it incorporates untrusted data into its long-term instruction set.
- Ingestion points: User-provided correction messages are processed in
references/lesson-template.mdandreferences/coupling-template.md. Repository-level data (diffs and file trees) are ingested inreferences/curation-prompt.mdandreferences/bootstrap-scan-prompt.md. - Boundary markers: The prompt templates do not utilize explicit delimiters or instruction isolation (e.g., XML tags or "ignore embedded instructions" warnings) when processing external input.
- Capability inventory: The skill is capable of generating full replacements for instruction files and unified diffs (
references/improve-skill-prompt.md), which are intended to be applied to the agent'sSKILL.mdfiles. - Sanitization: No sanitization or validation of user-provided text is performed before it is interpolated into the generated lesson files or skill updates.
- [COMMAND_EXECUTION]: The workflow relies on executing
git log --statand generating directory tree listings to provide the agent with project context for curation and bootstrapping. These are standard operations for development tools and do not represent arbitrary command execution risks, but involve direct interaction with the host environment's version control system.
Audit Metadata