self-improving-agent
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses local shell commands such as
grep,sed,wc, andfindto analyze and manage instructions and memory files within the project root and the user's home directory (~/.claude/). These operations are restricted to the local environment and are necessary for the skill's primary functionality. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from auto-captured memory (
MEMORY.md) and tool output via aPostToolUsebash hook (error-capture.sh). This data is processed to generate suggestions for project rules, which could potentially be influenced by content within the captured data. - Ingestion points: Analyzes
MEMORY.mdfrom the project's memory directory and reads from theCLAUDE_TOOL_OUTPUTenvironment variable during the error capture process. - Boundary markers: None explicitly defined in the automation logic to separate user-provided instructions from auto-captured memory patterns during processing.
- Capability inventory: The skill has the ability to read and modify project configuration files (
CLAUDE.md,.claude/rules/*.md) and execute shell scripts as part of the Claude Code hook system. - Sanitization: The skill identifies patterns but does not explicitly sanitize the content of memory entries before interpolating them into suggested instructions or rule files.
Audit Metadata