skill-ab-optimizer
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to run test suites against target skills, as described in Phase 2 of the workflow. This process involves invoking the agent within the context of the target skill, which can trigger the execution of shell commands or scripts defined in those files.
- [DATA_EXFILTRATION]: Through its allowed-tools (WebFetch and Read), the skill has the capacity to read sensitive local files and communicate with external web servers. While no specific exfiltration logic or malicious URLs are present, the tool combination provides a potential path for data transmission.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of processing external skill instructions. 1. Ingestion points: The skill reads the SKILL.md and reference files of the target being optimized (Phase 0, workflow.md). 2. Boundary markers: Absent; there are no instructions to use delimiters or ignore embedded commands within the input skills. 3. Capability inventory: High-privilege tools such as Bash, Write, and Edit are available to the agent. 4. Sanitization: Absent; the skill does not perform validation or filtering on the instructions it ingests before execution.
Audit Metadata