skills/simota/agent-skills/gauge/Gen Agent Trust Hub

gauge

Warn

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes third-party SKILL.md files for auditing. Malicious content within these files could potentially influence the agent's behavior or manipulate the results of the compliance check.\n
  • Evidence: The SCAN phase in SKILL.md and the normalization-checklist.md describe the ingestion of target skill files for analysis.\n- [DYNAMIC_EXECUTION]: The skill includes a self-evolution protocol that enables it to autonomously update its own instruction files in the reference/ directory. This dynamic modification of instructions based on external research constitutes a form of dynamic execution for an AI agent.\n
  • Evidence: The reference/self-evolution.md file defines the UPDATE phase for Level A and Level B changes to the skill's reference documentation.\n- [EXTERNAL_DOWNLOADS]: The agent performs web research to gather information for updating its logic, referencing external domains such as Anthropic's documentation, ArXiv, and community forums.\n
  • Evidence: reference/web-sources.md identifies several external sources used to support the EVOLVE workflow.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — gauge