gemini-md-improver

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill reads and evaluates local documentation files which could contain untrusted data, representing an indirect prompt injection surface. Evidence chain: 1. Ingestion points: SKILL.md (via file discovery). 2. Boundary markers: Absent. 3. Capability inventory: Uses shell commands for discovery and the Edit tool for updates. 4. Sanitization: Absent. This risk is mitigated by the explicit requirement for human review and approval before any modifications are applied in Phase 4 and 5.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 02:08 PM
Security Audit — agent-trust-hub — gemini-md-improver