ml-training-recipe

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external content such as research papers, datasets, and code repositories, which serves as a surface for indirect prompt injection.\n
  • Ingestion points: External research papers, datasets, documentation, and code (SKILL.md).\n
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are defined in the skill manifest to prevent the agent from following instructions found within the research materials.\n
  • Capability inventory: The skill records results in the outputs/ directory. The associated researcher and verifier agents typically possess web searching and file system capabilities.\n
  • Sanitization: The manifest does not specify any sanitization, filtering, or validation steps for the external data before it is processed by the agents.\n- [SAFE]: No malicious patterns such as hardcoded credentials, obfuscation, or unauthorized remote code execution were found in the skill metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 01:46 AM
Security Audit — agent-trust-hub — ml-training-recipe