improve-agent-workflow
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill implements a workflow that involves reading untrusted project data and performing file writes, creating a surface for indirect prompt injection.\n
- Ingestion points: The skill reads project governing instructions, logs, traces, diffs, and review comments to diagnose workflow issues (detailed in
commands/audit.md).\n - Boundary markers: The instructions emphasize respecting "Authority boundaries" and relying on "human committers" for final approval, though no specific technical delimiters are enforced for ingested content.\n
- Capability inventory: The skill is authorized to implement improvements by changing the "smallest owning surface," which includes editing project files, instructions, skills, and tools (detailed in
commands/improve.md).\n - Sanitization: The methodology requires the agent to separate observed behavior from inference and restricts actions to those explicitly authorized by human oversight.\n- [EXTERNAL_DOWNLOADS]: The skill references a repository for lineage and principle snapshots (
github.com/lidessen/skills.git). This resource is owned by the skill author and is used for metadata and principle synchronization.
Audit Metadata