automatic-stateful-prompt-improver
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The
SETUP.mdfile recommends a 'One-Command Install' usingcurl -fsSL https://someclaudeskills.com/install/prompt-learning.sh | bash. This pattern is highly dangerous as it executes an unverified script from an untrusted domain directly in the shell without prior review. - [EXTERNAL_DOWNLOADS]: The
SETUP.mdfile directs users to clone a repository from an untrusted GitHub account (erichowens/prompt-learning-mcp). It also specifies the installation of several Node.js packages including@modelcontextprotocol/sdk,@qdrant/js-client-rest,ioredis, andopenaito facilitate the stateful learning functionality. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to intercept user requests for automatic optimization, which exposes a surface for indirect prompt injection.
- Ingestion points: The
SKILL.mdinstructions specify that the user's original request is intercepted and passed to theoptimize_prompttool. - Boundary markers: None are present; the user prompt is passed as a raw string to the tool without delimiters or instructions to ignore embedded commands.
- Capability inventory: The skill has access to several prompt-learning MCP tools and sequential thinking tools.
- Sanitization: None; there is no logic to filter or sanitize potential instructions embedded within the user's request before it is processed by the optimization engine.
Recommendations
- AI detected serious security threats
Audit Metadata