improve-skill

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill modifies other skill files based on untrusted data from the chat history.
  • Ingestion points: The skill reads the current chat session (untrusted user data) and existing prompt files located in the .kiro/prompts/ directory.
  • Boundary markers: Absent. There are no delimiters or specific instructions provided to the agent to disregard potential adversarial instructions contained within the user feedback during the improvement process.
  • Capability inventory: The skill has the capability to read and update files within the .kiro/prompts/ directory.
  • Sanitization: Absent. No sanitization or verification process is defined for the input received from the chat session before it is incorporated into the modified skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 12:44 AM
Security Audit — agent-trust-hub — improve-skill