improve-doc

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface common to document processing tools, as it ingests and analyzes untrusted content from external markdown files.
  • Ingestion points: The skill reads the full content of a file specified by the user in the Path argument.
  • Boundary markers: The instructions use markdown headers and blockquotes to present analysis, but do not employ strict LLM-level boundary delimiters to distinguish the document content from the skill's operational instructions.
  • Capability inventory: The skill has the capability to read and overwrite files on the local filesystem.
  • Sanitization: The risk is significantly mitigated by the 'Gates' mechanism, which mandates explicit user commands (start) to enter the refinement phase and individual confirmations (yes/skip) before any changes are committed to the disk. This ensures that any instructions embedded in the target document cannot trigger autonomous malicious actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:16 AM
Security Audit — agent-trust-hub — improve-doc