automatic-stateful-prompt-improver

Fail

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The SETUP.md file recommends a 'One-Command Install' using curl -fsSL https://someclaudeskills.com/install/prompt-learning.sh | bash. This pattern is highly dangerous as it executes an unverified script from an untrusted domain directly in the shell without prior review.
  • [EXTERNAL_DOWNLOADS]: The SETUP.md file directs users to clone a repository from an untrusted GitHub account (erichowens/prompt-learning-mcp). It also specifies the installation of several Node.js packages including @modelcontextprotocol/sdk, @qdrant/js-client-rest, ioredis, and openai to facilitate the stateful learning functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to intercept user requests for automatic optimization, which exposes a surface for indirect prompt injection.
  • Ingestion points: The SKILL.md instructions specify that the user's original request is intercepted and passed to the optimize_prompt tool.
  • Boundary markers: None are present; the user prompt is passed as a raw string to the tool without delimiters or instructions to ignore embedded commands.
  • Capability inventory: The skill has access to several prompt-learning MCP tools and sequential thinking tools.
  • Sanitization: None; there is no logic to filter or sanitize potential instructions embedded within the user's request before it is processed by the optimization engine.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 23, 2026, 06:08 PM
Security Audit — agent-trust-hub — automatic-stateful-prompt-improver