skill-pipeline

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill features an 'Outer Loop' designed for cross-session learning. It utilizes a harness-updater tool to modify the agent's primary instruction files (e.g., CLAUDE.md, AGENTS.md) by promoting patterns identified during task execution. While the skill documentation states these writes are human-gated, the capability to modify the agent's governing rules based on dynamic data represents a significant risk vector.
  • [INDIRECT_PROMPT_INJECTION]: The orchestrator is designed to ingest and process arbitrary task descriptions, issue lists, and specifications from external sources, which constitutes a large attack surface for indirect prompt injection.
  • Ingestion points: Task classification logic in SKILL.md and references/classification-rules.md processes untrusted descriptions to determine pipeline routing.
  • Boundary markers: The skill uses 'Intent Frames' produced by intent-framed-agent to restate and confirm the task plan, which provides a layer of human-in-the-loop validation to mitigate unintended command execution.
  • Capability inventory: The pipeline dispatches tasks to skills with high-impact capabilities, including automated code patching (self-healing), test execution (verify-gate), and instruction file updates (harness-updater).
  • Sanitization: Sanitization is delegated to the simplify-and-harden skill, which is explicitly tasked with scanning for injection vectors and other security vulnerabilities in the code produced or modified.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 08:41 AM
Security Audit — agent-trust-hub — skill-pipeline