videocut-self-update

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCEPRIVILEGE_ESCALATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to automatically ingest context and user feedback to rewrite core instruction files. This creates a surface where instructions embedded in external content processed by the agent could be persistently integrated into its persona.
  • Ingestion points: The skill triggers on phrases like "刚才失败了" (just failed) or "记录一下" (record this) in SKILL.md.
  • Boundary markers: Absent. The skill instructions specifically direct the agent to "not ask 'what problem'" and to integrate rules directly into the body of existing files.
  • Capability inventory: The skill modifies /CLAUDE.md and /*/tips/*.md via file writing.
  • Sanitization: Absent. The process lacks validation or filtering of the context being integrated.
  • [PERSISTENCE]: By modifying the /CLAUDE.md persona file, the skill enables changes to the agent's behavior that persist across all future sessions. A successful injection via this mechanism would result in long-term compromise of the agent's instructions.
  • [PRIVILEGE_ESCALATION]: The skill requests the capability to modify high-level configuration files that define the agent's core identity and constraints. The instruction to perform these updates automatically without human-in-the-loop verification ("直接从上下文分析"
  • analyze directly from context) bypasses standard review processes for modifying system-level instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:23 AM
Security Audit — agent-trust-hub — videocut-self-update