improve-skill
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill modifies other skill files based on untrusted data from the chat history.
- Ingestion points: The skill reads the current chat session (untrusted user data) and existing prompt files located in the .kiro/prompts/ directory.
- Boundary markers: Absent. There are no delimiters or specific instructions provided to the agent to disregard potential adversarial instructions contained within the user feedback during the improvement process.
- Capability inventory: The skill has the capability to read and update files within the .kiro/prompts/ directory.
- Sanitization: Absent. No sanitization or verification process is defined for the input received from the chat session before it is incorporated into the modified skill files.
Audit Metadata