skill-evolution

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily a documentation and instructional framework for managing other skills. It does not contain executable code, scripts, or network requests.
  • [DATA_EXPOSURE]: The skill uses local memory files (mistakes.md, patterns.md) for logging execution metrics and feedback, which is standard practice for agent memory management.
  • [INDIRECT_PROMPT_INJECTION]: While the skill involves evolving other skills based on execution data (which could be influenced by untrusted inputs), it explicitly mandates human review in its process ('4. REVIEW: Human approval required before applying') before any changes are saved to file, effectively mitigating the risk of automated injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:07 PM
Security Audit — agent-trust-hub — skill-evolution