videocut-self-update
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCEPRIVILEGE_ESCALATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to automatically ingest context and user feedback to rewrite core instruction files. This creates a surface where instructions embedded in external content processed by the agent could be persistently integrated into its persona.
- Ingestion points: The skill triggers on phrases like "刚才失败了" (just failed) or "记录一下" (record this) in
SKILL.md. - Boundary markers: Absent. The skill instructions specifically direct the agent to "not ask 'what problem'" and to integrate rules directly into the body of existing files.
- Capability inventory: The skill modifies
/CLAUDE.mdand/*/tips/*.mdvia file writing. - Sanitization: Absent. The process lacks validation or filtering of the context being integrated.
- [PERSISTENCE]: By modifying the
/CLAUDE.mdpersona file, the skill enables changes to the agent's behavior that persist across all future sessions. A successful injection via this mechanism would result in long-term compromise of the agent's instructions. - [PRIVILEGE_ESCALATION]: The skill requests the capability to modify high-level configuration files that define the agent's core identity and constraints. The instruction to perform these updates automatically without human-in-the-loop verification ("直接从上下文分析"
- analyze directly from context) bypasses standard review processes for modifying system-level instructions.
Audit Metadata