evolve

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by processing 'learned instincts' to generate new agent instructions and skills. * Ingestion points: The skill ingests 'instincts' (which may be derived from external or untrusted data sources) to categorize and synthesize higher-level constructs. * Boundary markers: There are no explicit markers or instructions to ignore potential commands embedded within the instincts during the synthesis process. * Capability inventory: The skill possesses the capability to write files to the user's local filesystem (~/.claude/evolved/). * Sanitization: The instructions do not describe any sanitization or validation of the input instincts before they are incorporated into generated content.
  • [COMMAND_EXECUTION]: The skill performs local filesystem operations by saving generated skills, rules, and commands to the ~/.claude/evolved/ directory. While this is the stated functional purpose, generating and writing instructional content based on untrusted inputs represents a potential risk if subsequent agents or skills load these files without review.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 04:19 AM
Security Audit — agent-trust-hub — evolve