skills/hubvue/skills/code-evolver/Gen Agent Trust Hub

code-evolver

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious instructions, unauthorized file access, or network communications were found. The skill is an administrative utility for project documentation.\n- [PROMPT_INJECTION]: The skill manages an indirect prompt injection surface by converting conversation history into agent behavioral rules. Evidence chain: (1) Ingestion points: Session conversation history; (2) Boundary markers: The skill requires structured formatting but lacks explicit input delimiters; (3) Capability inventory: Modifies steering files (.cursor/rules, AGENTS.md, CLAUDE.md) that constrain future agent actions; (4) Sanitization: Comprehensive decision logic (Update/Merge/Conflict/Ignore) and a quality checklist requiring functional few-shot examples mitigate the risk of adopting malicious or unintended rules.\n- [DATA_EXFILTRATION]: The skill's operations are confined to local configuration files and do not involve network requests or the handling of sensitive credentials.\n- [COMMAND_EXECUTION]: The skill does not invoke shell commands or execute code. Its output is limited to text content for documentation and configuration markdown files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 07:20 AM