improve-skills

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs Git, the GitHub CLI, and the Asta utility to manage repository branches, issues, and PRs as part of the skill improvement cycle.\n- [REMOTE_CODE_EXECUTION]: The skill executes evaluation code and benchmark suites using uv and docker containers based on content from cloned vendor repositories.\n- [EXTERNAL_DOWNLOADS]: The skill downloads internal development and benchmarking repositories from the allenai GitHub organization to initialize the workspace.\n- [CREDENTIALS_UNSAFE]: The skill acquires authentication tokens via the asta auth print-token command to authorize access to vendor resources.\n- [PROMPT_INJECTION]: The skill ingests data from GitHub issue bodies and repository content, creating an entry point for indirect prompt injection that could influence the agent's workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 08:02 AM
Security Audit — agent-trust-hub — improve-skills