skill-optimizer
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user corrections stored in a local SQLite database to update instructions, creating a vector for indirect injection.
- Ingestion points: Reads from
~/.pro-workflow/data.db(specificallylearn-rulerows). - Boundary markers: None specified; instructions do not detail how external data is delimited before being processed by the optimizer LLM.
- Capability inventory: The skill has the ability to overwrite local
SKILL.mdfiles and perform network operations via LLM provider APIs. - Sanitization: Not explicitly present; the skill relies on the LLM's "optimizer" and "evaluator" logic to filter content.
- [COMMAND_EXECUTION]: The skill instructions include the execution of shell commands to interact with the local file system and databases.
- Evidence: Use of
/skill-optimizeas a primary entry point andsqlite3for inspecting optimization results in~/.pro-workflow/data.db. - [DYNAMIC_EXECUTION]: The skill is designed for self-modification, which involves programmatically rewriting its own source instructions at runtime.
- Evidence: The
updateandslow updatestages generate and apply patches to theSKILL.mdfile based on LLM output.
Audit Metadata