tune-skill

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and process the content of other agent skills, which creates a surface for indirect prompt injection.
  • Ingestion points: The skill reads external files (existing skills) and user-provided complaints in the 'Hear the complaint' and 'Diagnose root cause vs symptom' sections.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' commands when reading or auditing the content of the target skill.
  • Capability inventory: The agent has the ability to modify local files and spawn sub-agents to process the target skill's content.
  • Sanitization: There is no evidence of sanitization or filtering of the instructions contained within the skills being edited before they are evaluated or passed to the auditing sub-agent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 01:24 PM
Security Audit — agent-trust-hub — tune-skill