self-improving-agent

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses local shell commands such as grep, sed, wc, and find to analyze and manage instructions and memory files within the project root and the user's home directory (~/.claude/). These operations are restricted to the local environment and are necessary for the skill's primary functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from auto-captured memory (MEMORY.md) and tool output via a PostToolUse bash hook (error-capture.sh). This data is processed to generate suggestions for project rules, which could potentially be influenced by content within the captured data.
  • Ingestion points: Analyzes MEMORY.md from the project's memory directory and reads from the CLAUDE_TOOL_OUTPUT environment variable during the error capture process.
  • Boundary markers: None explicitly defined in the automation logic to separate user-provided instructions from auto-captured memory patterns during processing.
  • Capability inventory: The skill has the ability to read and modify project configuration files (CLAUDE.md, .claude/rules/*.md) and execute shell scripts as part of the Claude Code hook system.
  • Sanitization: The skill identifies patterns but does not explicitly sanitize the content of memory entries before interpolating them into suggested instructions or rule files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:32 PM