skill-pipeline
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill features an 'Outer Loop' designed for cross-session learning. It utilizes a
harness-updatertool to modify the agent's primary instruction files (e.g.,CLAUDE.md,AGENTS.md) by promoting patterns identified during task execution. While the skill documentation states these writes are human-gated, the capability to modify the agent's governing rules based on dynamic data represents a significant risk vector. - [INDIRECT_PROMPT_INJECTION]: The orchestrator is designed to ingest and process arbitrary task descriptions, issue lists, and specifications from external sources, which constitutes a large attack surface for indirect prompt injection.
- Ingestion points: Task classification logic in
SKILL.mdandreferences/classification-rules.mdprocesses untrusted descriptions to determine pipeline routing. - Boundary markers: The skill uses 'Intent Frames' produced by
intent-framed-agentto restate and confirm the task plan, which provides a layer of human-in-the-loop validation to mitigate unintended command execution. - Capability inventory: The pipeline dispatches tasks to skills with high-impact capabilities, including automated code patching (
self-healing), test execution (verify-gate), and instruction file updates (harness-updater). - Sanitization: Sanitization is delegated to the
simplify-and-hardenskill, which is explicitly tasked with scanning for injection vectors and other security vulnerabilities in the code produced or modified.
Audit Metadata