Is skills/skill-improver safe?
Yes. skills/skill-improver is safe to install. Oathe's behavioral security audit gave the skill-improver skill by skills a trust score of 86/100 with 6 findings, none critical or high.
https://github.com/trailofbits/skills/tree/main/plugins/code-improver/skills/skill-improver
Is skills/skill-improver safe to install?
The skill-improver SKILL.md from Trail of Bits is a clean orchestration entry point with no malicious instructions, hidden content, encoding tricks, or data exfiltration patterns; it also includes an explicit security-positive constraint preventing the agent from improvising the loop inline when tools are unavailable. The primary residual risk is architectural: the skill's entire substantive logic lives in an external JavaScript workflow (workflows/improve.js) that was not present in the audited package and could not be inspected, and the improvement loop additionally depends on a second unaudited marketplace plugin (plugin-dev:skill-reviewer). Installation is reasonable for users who trust Trail of Bits as a publisher and are willing to accept these unverified transitive dependencies.
What security issues were found in skills/skill-improver?
Category Scores
Findings (6)
MEDIUM Core function delegates to unaudited external workflow (improve.js) -22 ▶
The audited package contains only SKILL.md. The skill's entire substantive action — the review loop, scope guard, ledger, fix verification, and finalize pass — lives in workflows/improve.js from the parent plugin, which was not present in the audited directory and could not be inspected. Trust in this skill is necessarily conditional on trust in that unaudited JavaScript file and whatever agents it spawns.
LOW Full installed-skill inventory enumeration exposed to agent context -12 ▶
The fallback skill resolution path runs Glob(pattern='**/SKILL.md') across the entire working tree, injecting the full list of installed skills and their paths into the agent's context. Combined with the find scan of ~/.claude and ~/.codex, the agent learns the user's complete Claude plugin installation layout, which is passed downstream to the workflow and reviewer subagents.
LOW Agent directed to traverse user's Claude configuration directories -8 ▶
Step 2 of the skill explicitly instructs the agent to search ~/.claude and ~/.codex with a find command. While scoped to locating a specific file path, this reveals the configuration directory tree to the agent context. This is broader than necessary — the skill could restrict discovery to CLAUDE_PLUGIN_ROOT alone.
LOW Second unaudited dependency: plugin-dev:skill-reviewer marketplace plugin -10 ▶
The skill mandates installation of plugin-dev:skill-reviewer from claude-plugins-official. The review verdicts from this agent determine what fixes the loop applies. A compromised reviewer could direct the fixer to introduce subtle vulnerabilities under the guise of 'improvements', or to weaken security-related skill guarantees. This audit did not evaluate plugin-dev:skill-reviewer.
INFO Canary file opens attributable to monitoring framework, not skill behavior -5 ▶
Two rounds of canary file accesses appear in auditd PATH records. Timing analysis places the first round before the git clone (audit system baseline) and the second round after install completion (post-install integrity verification). No instructions in SKILL.md direct the agent to read .env, SSH keys, AWS credentials, or similar files. All canary hashes verified intact by the monitoring system.
INFO Clean installation from known Trail of Bits repository 0 ▶
The sparse clone sourced from github.com/trailofbits/skills.git (a public Trail of Bits repository) extracted only the target subpath, made no changes outside the destination directory, and cleaned up the temporary clone. Post-install connection diff shows no new persistent network connections or listening ports.
Should I install skills/skill-improver?
Oathe's verdict for skills/skill-improver is SAFE with a trust score of 86/100. Recommendation: Install with caution.