self-improve
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to run arbitrary shell commands specified in the
benchmark_commandsetting and perform extensive Git operations (worktree creation, merging, tagging, and pushing) within a target repository. The risk is mitigated by a mandatory interactive trust confirmation step required before the autonomous loop begins. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and acts upon research briefs and plans generated by LLM agents. These inputs represent an attack surface where malicious data could influence the autonomous loop's behavior or target repository content.
- Ingestion points: The skill reads JSON research briefs in Step 5 and plan documents in Step 7 of the improvement loop defined in
SKILL.md. - Boundary markers: Includes Architect and Critic review steps (Step 6) to evaluate plans against diversity and quality rules (H001-H003).
- Capability inventory: The skill possesses the ability to execute shell commands and modify files in the target repository.
- Sanitization: Uses
scripts/validate.shto enforce JSON schema validation and uses asealed_filesmechanism to prevent the loop from modifying critical benchmark or evaluation code. - [DYNAMIC_EXECUTION]: The core functionality of the skill involves the runtime creation of code modifications and the subsequent execution of that modified code to evaluate performance improvements.
Audit Metadata