candid-improve
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill logic is focused on text processing and follows established patterns for developer tools including state management in a hidden project directory.
- [DATA_EXPOSURE]: Data access is limited to the current session context, user-specified files, and local state files within the .candid directory. There is no evidence of unauthorized access to sensitive credentials or system files.
- [COMMAND_EXECUTION]: The use of shell commands like mkdir and configuration tools like jq is transparently documented and limited to managing the skill's own operational state.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external text artifacts which represents an indirect prompt injection surface. However, the instructions include explicit constraints (e.g., 'Improve the artifact as it is', 'Change only what the critique justifies') that effectively mitigate the risk of the agent being diverted from its primary task.
Audit Metadata