skill-improve
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill employs a load-time shell execution pattern to resolve configuration:
!bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys automation``. This interaction with a local script is used for environment setup and does not involve untrusted input or exfiltration patterns. - [INDIRECT_PROMPT_INJECTION]: The skill reads and analyzes external
SKILL.mdfiles (Phase 3). This ingestion point for potentially untrusted markdown content represents a surface for prompt injection, though the risk is mitigated by the skill's targeted diagnostic logic and the requirement for user consent before any file modifications are applied.
Audit Metadata