ml-training-recipe
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external content such as research papers, datasets, and code repositories, which serves as a surface for indirect prompt injection.\n
- Ingestion points: External research papers, datasets, documentation, and code (SKILL.md).\n
- Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are defined in the skill manifest to prevent the agent from following instructions found within the research materials.\n
- Capability inventory: The skill records results in the
outputs/directory. The associatedresearcherandverifieragents typically possess web searching and file system capabilities.\n - Sanitization: The manifest does not specify any sanitization, filtering, or validation steps for the external data before it is processed by the agents.\n- [SAFE]: No malicious patterns such as hardcoded credentials, obfuscation, or unauthorized remote code execution were found in the skill metadata.
Audit Metadata