skills/wondelai/skills/improve-app/Gen Agent Trust Hub

improve-app

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data originating from project documentation and external user evidence such as support tickets and reviews.
  • Ingestion points: The agent reads state and content from files in the docs/ directory, including IMPROVE-APP-PLAN.md, CUSTOMER.md, DESIGN.md, POSITIONING.md, EXPERIMENTS.md, and PRODUCT.md.
  • Boundary markers: The operating rules instruct the agent to read artifacts before writing and to preserve existing content in the files when extending them.
  • Capability inventory: The skill is authorized to perform file write operations within the docs/ directory and to invoke sub-skills.
  • Sanitization: No specific sanitization or filtering logic is defined for external feedback or evidence data processed during analysis.
  • [COMMAND_EXECUTION]: The instructions include a fallback mechanism that suggests a shell command for the user to install missing components.
  • Evidence: The agent is instructed to suggest the command npx skills add wondelai/skills/<slug> --global if a required skill is not available.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the fetching of external resources from the author's repository to support the orchestration journey.
  • Evidence: The workflow references and suggests downloading sub-skills from the wondelai/skills/ namespace.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 12:04 PM
Security Audit — agent-trust-hub — improve-app