skill-improver
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection because it is designed to ingest and act upon the content of external SKILL.md files.
- Ingestion points: The agent reads skill files from the SKILL_PATH provided by the user.
- Boundary markers: The instructions lack specific delimiters or instructions for the agent to ignore embedded commands within the target files.
- Capability inventory: The skill workflow grants the agent the ability to modify files and execute the skill-reviewer agent based on the input data.
- Sanitization: The skill does not implement validation or sanitization of the content found within the target skill files.
- [EXTERNAL_DOWNLOADS]: The skill mentions the plugin-dev plugin and the Trail of Bits repository. This reference is for manual setup by the user and does not involve the agent performing automated or unverified downloads.
Audit Metadata