improve-ic-skill
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and modify external skill files and evaluation configurations, creating an attack surface where malicious instructions embedded in those files could influence the agent.
- Ingestion points: The agent reads
SKILL.md,.claude/upstream.md, andevaluations/<skill-name>.json(Steps 1 and 6). - Boundary markers: No explicit delimiters or instructions to ignore embedded commands within the ingested files are specified.
- Capability inventory: The agent has the authority to execute repository commands, including
npm run validate,git log,skill-validator, andnode scripts/evaluate-skills.js(Steps 1, 2, 5, and 7). - Sanitization: The instructions do not describe sanitization or filtering of the content read from the files before processing.
- [COMMAND_EXECUTION]: The skill instructs the agent to perform several shell-based operations and execute local scripts to maintain project quality and verify changes.
- Operations: Execution of
npm run validatefor project consistency,git logfor change history,skill-validatorfor LLM-based quality scoring, andnode scripts/evaluate-skills.jsfor running regression tests.
Audit Metadata