documentation-standards
Warn
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [DYNAMIC_EXECUTION]: The skill implements a self-modification pattern under the 'Self-Evolving Skill' header. It explicitly instructs the agent to 'fix this file immediately' and update SKILL.md with workarounds or changes in parameters. This runtime modification of the skill's own instructions represents a security risk similar to self-modifying code.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external markdown documentation. Because it also contains instructions to self-modify based on workarounds needed during execution, there is a risk that an attacker-controlled document could trick the agent into writing malicious instructions into its own SKILL.md file.
- Ingestion points: Markdown content processed by the agent in SKILL.md's context (e.g., during review or creation tasks).
- Boundary markers: Absent. There are no delimiters or warnings provided to prevent the agent from being influenced by data within processed documents.
- Capability inventory: The agent is directed to write to its own configuration (SKILL.md) and has access to Read, Glob, and Grep tools.
- Sanitization: Absent. The skill does not provide instructions to filter or escape content from documentation before it affects the self-evolution process.
- [PROMPT_INJECTION]: The skill uses high-pressure directives ('fix this file immediately, don't defer') that command the agent to override its current state. If a user provides input that triggers an error necessitating a 'fix', the agent may adopt unintended rules.
- [METADATA_POISONING]: The skill's description field in the YAML frontmatter ends abruptly ('Use whenever the user is writing or.'), which may be intended to leave the agent's context open or is a sign of deceptive metadata.
Audit Metadata