self-improve
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to extract 'lessons' from user revisions and feedback, storing them in a persistent log and injecting them into the system prompt for future tasks. This creates a surface for indirect prompt injection.
- [PROMPT_INJECTION]: Evidence Chain: 1. Ingestion points: User revisions, explicit user feedback, and task outcomes (SKILL.md). 2. Boundary markers: The skill uses basic headers like '## Lessons Learned' but lacks robust delimiters or instructions to ignore embedded commands within the lessons. 3. Capability inventory: 'file:read' and 'file:write' permissions are used to manage the improvement log (SKILL.md). 4. Sanitization: No sanitization or validation of the extracted lesson text is mentioned, allowing raw user-influenced content to be treated as a behavioral rule.
Audit Metadata