autoskill
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill extracts preferences and corrections from session history to modify its own or other skills' instructions. This creates a surface for indirect prompt injection (Category 8), as an attacker could provide feedback designed to subvert the agent's behavior which would then be codified into the skill files. Evidence:
- Ingestion points: Conversation history in the active coding session (SKILL.md).
- Boundary markers: None explicitly defined during signal detection.
- Capability inventory: File modification (
Edit the target file) and shell execution (git commit). - Sanitization: None described, relying solely on LLM quality filtering and human review.
- [COMMAND_EXECUTION]: The skill utilizes system commands to manage changes. It is instructed to use
git committo record changes to skill files. This is a legitimate use of local tooling for the skill's stated purpose of maintaining versioned configurations.
Audit Metadata