improve-code-quality
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill maintains state by reading existing project documentation and ingesting user responses from an intake questionnaire.
- Ingestion points: Intake questions (Operating Rule 2) and project files such as
docs/IMPROVE-CODE-QUALITY-PLAN.md(Operating Rule 1). - Boundary markers: Absent; there are no explicit delimiters or warnings to ignore instructions within the project files.
- Capability inventory: The skill utilizes file system read/write capabilities and invokes other agent skills based on their slugs.
- Sanitization: Not explicitly defined; the skill relies on the agent's context processing to handle interpolated data.
- [EXTERNAL_DOWNLOADS]: The instructions recommend installing supplemental skills from the author's repository using the command
npx skills add wondelai/skills/<slug>. These represent external dependencies fetched from a remote registry. - [COMMAND_EXECUTION]: The skill performs project analysis using
git logto identify code churn and suggests the use ofnpxfor tool installation.
Audit Metadata