self-improving-agent
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for learning from session outcomes, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: The system ingests data from
sessions.jsonl(session logs) andMEMORY.md(captured observations) to identify patterns. - Boundary markers: There are no explicit boundary markers or 'ignore' instructions implemented in the scripts to delimit untrusted session data from the promotion logic.
- Capability inventory: The
rule_promoter.pyscript has the capability to write toCLAUDE.mdand.claude/rules/, directly modifying the agent's long-term instruction set. - Sanitization: The Python scripts do not perform specific sanitization or filtering of session content before formatting it into candidate rules.
- [DYNAMIC_EXECUTION]: The skill includes several Python scripts in the
scripts/directory used for memory curation, pattern extraction, and rule management. These scripts utilize standard Python libraries and do not incorporate remote code, use unsafe deserialization, or perform network requests. - [COMMAND_EXECUTION]: The skill facilitates the execution of its local utility scripts via documented shell commands. These scripts perform localized file system operations on memory and rule files consistent with the skill's primary self-improvement functionality.
Audit Metadata