skill-improver

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to read, audit, and modify other SKILL.md files. This creates a surface where instructions within those files could potentially influence the agent's logic during the audit or refactor process.
  • Ingestion points: Accesses SKILL.md files located in the workspace and the .atl/skill-registry.md index file.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard instructions found within the files it is auditing.
  • Capability inventory: The skill can read and write local files and execute the gentle-ai CLI tool.
  • Sanitization: No sanitization or safety-filtering of the content retrieved from audited skills is mentioned.
  • [COMMAND_EXECUTION]: The skill triggers the execution of gentle-ai skill-registry refresh to update its internal index of skills. This command is a project-specific utility for synchronizing the skill metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 03:16 PM
Security Audit — agent-trust-hub — skill-improver