auto-learner
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and process 'execution_outcomes', 'execution_patterns', and 'input_output_pairs' to autonomously modify agent behavior, which creates a surface for indirect prompt injection where malicious instructions in task data could poison future skill logic.\n
- Ingestion points: execution data and input/output pairs entering via mechanisms in SKILL.md.\n
- Boundary markers: Absent; no instructions for delimiters or ignoring embedded commands are provided.\n
- Capability inventory: The skill includes instructions to update and deploy improvements to other skills.\n
- Sanitization: Absent; no logic for sanitizing or filtering the content of the execution data is specified.\n- [NO_CODE]: The skill relies entirely on natural language instructions and contains no executable code or scripts.
Audit Metadata