simplify-and-harden

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill implements a 'Learning Loop' that directs the agent to modify its own system configuration and instruction files. Evidence in SKILL.md under 'Self-Improvement Integration' describes promoting patterns into agent context files like CLAUDE.md and AGENTS.md, effectively allowing the agent to rewrite its own operational rules.
  • [INDIRECT_PROMPT_INJECTION]: The automated promotion of rules from reviewed code to system instructions creates an attack surface for indirect injection. 1. Ingestion points: Code diffs and modified files processed during the review phase (SKILL.md). 2. Boundary markers: None specified for the learning loop promotion process. 3. Capability inventory: File-write access to persistent agent instruction files (SKILL.md). 4. Sanitization: No validation or sanitization is described for the extracted patterns before they are appended to system-level instructions.
  • [EXTERNAL_DOWNLOADS]: Fetches skill components from the author's GitHub repository as part of the installation process. Evidence: SKILL.md contains commands for 'gh skill install' and 'npx skills add' targeting the 'pskoett/pskoett-skills' repository.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 08:41 AM
Security Audit — agent-trust-hub — simplify-and-harden