hillclimb
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository's
CHOICES.mdfile to determine thescope,metric, andgatefor its automated improvement cycles. - Ingestion points: The skill parses parameters from
CHOICES.mdin Step 1 of the loop. - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands within the parsed parameters are mentioned.
- Capability inventory: The skill possesses the ability to propose Pull Requests (Step 3), execute arbitrary code modifications via the
/taskskill (Step 5), and write data to theobjective_metricsfile (Step 2 and 6). - Sanitization: There is no evidence of sanitization or validation of the input parameters parsed from the repository files before they are used to drive the improvement loop.
Audit Metadata