skill-architecture

Fail

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONPERSISTENCEDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill architecture documentation references a domain flagged as malicious (nathanonn.com) as a primary source for its 'Self-Evolution Protocol'. Automated security scans identified this domain as being on a blacklist, posing a risk to agents following these instructions to gather domain knowledge.
  • Evidence: [nathanonn.com](https://www.nathanonn.com/how-to-build-evolving-claude-code-rules/) found in references/evolution-log.md and references/theory-self-evolution.md.
  • The documentation also points to an untrusted third-party repository 191341025/Self-Evolving-Skill on GitHub as a reference for evolution protocols.
  • [INDIRECT_PROMPT_INJECTION]: The skill promotes a 'Self-Evolving Skill' architecture that enables a persistent attack surface for indirect prompt injection.
  • Ingestion points: The agent is instructed to use 'empirical observations' from its own execution (including potentially attacker-controlled script outputs or external content) to update its instructions.
  • Boundary markers: While logical 'admission gates' are mentioned, there are no technical delimiters or sanitization steps to prevent malicious content from being injected into the persistent SKILL.md file.
  • Capability inventory: The skill encourages providing the agent with the capability to edit its own SKILL.md and sibling references/ files.
  • Sanitization: The reflection protocol (references/post-execution-reflection.md) directs the agent to 'Fix the instruction that caused it' and 'Update SKILL.md instructions' without providing methods to escape or validate the new instructions, allowing potentially malicious payloads to be persisted across sessions.
  • [PERSISTENCE]: The skill provides detailed patterns for establishing persistence through shell hooks.
  • It describes a 'Hook Integration Pattern' in references/advanced-topics.md which uses hooks/hooks.json to register automated event handlers.
  • These hooks are merged into the user's global ~/.claude/settings.json file, allowing custom commands to run silently on Claude Code lifecycle events such as PreToolUse, PostToolUse, and Stop.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill documents and encourages the use of the ! + command`` syntax to inject shell command output into the skill context at load time.
  • While the provided examples (git branch, git log) are benign, the documentation highlights this as a primary feature for 'Dynamic Context Injection', which can be abused to execute commands or exfiltrate data silently when a skill is loaded.
  • Evidence: Examples found in SKILL.md under the 'Dynamic Context Injection' section.
Recommendations
  • AI detected serious security threats
  • Contains 3 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Oct 4, 2026, 05:34 AM
Security Audit — agent-trust-hub — skill-architecture