autoskill

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill extracts preferences and corrections from session history to modify its own or other skills' instructions. This creates a surface for indirect prompt injection (Category 8), as an attacker could provide feedback designed to subvert the agent's behavior which would then be codified into the skill files. Evidence:
  • Ingestion points: Conversation history in the active coding session (SKILL.md).
  • Boundary markers: None explicitly defined during signal detection.
  • Capability inventory: File modification (Edit the target file) and shell execution (git commit).
  • Sanitization: None described, relying solely on LLM quality filtering and human review.
  • [COMMAND_EXECUTION]: The skill utilizes system commands to manage changes. It is instructed to use git commit to record changes to skill files. This is a legitimate use of local tooling for the skill's stated purpose of maintaining versioned configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — autoskill