aeon-skill-repair
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from target
SKILL.mdfiles and externalerror_outputlogs to generate diagnostic dossiers and apply fixes. - Ingestion points: Target skill files and pasted error output logs from the run log.
- Capability inventory: File modification (edits local skill files), network operations (WebFetch on diagnostic sources).
- Boundary markers: No explicit delimiters or "ignore embedded instructions" warnings were found to separate instructions from diagnostic data.
- Sanitization: No sanitization or validation logic is described for processing external error log content.
- [DYNAMIC_EXECUTION]: The skill automatically applies instruction modifications to other skills based on its diagnostic logic. This involves generating and injecting instruction diffs into executable agent files, which are subsequently re-run.
- [COMMAND_EXECUTION]: The skill performs network requests via "WebFetch" on URLs extracted from target skills to verify source liveness (e.g., detecting 404s or redirects). This allows the agent to interact with arbitrary remote endpoints referenced in targeted files.
Audit Metadata