experiment
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes and iterates on external artifacts and configuration files, creating a surface for potential instruction injection.
- Ingestion points: The agent reads the experiment definition from
CARD.mdand the target content from a "mutable surface" file (SKILL.md). - Boundary markers: The skill references an "autonomy gate" to verify the safety of the environment, but does not define specific technical delimiters or instruction isolation for the content being optimized (SKILL.md).
- Capability inventory: The skill performs file writes (editing the mutable surface), version control operations (
git checkout,git commit,git reset), and executes a local script (tools/experiment_log.py) (SKILL.md). - Sanitization: There are no explicit instructions for sanitizing or escaping the content of the artifacts being modified (SKILL.md).
- [DYNAMIC_EXECUTION]: The skill is designed to have the agent iteratively modify a "mutable surface" (which may be code) and then execute a "read-only harness" to evaluate the changes.
- Evidence: The workflow involves editing a target file and running it via a harness to generate a
results.tsvlog (SKILL.md). - [COMMAND_EXECUTION]: The skill utilizes shell commands to manage the experimentation lifecycle and logging.
- Evidence: The instructions explicitly direct the agent to use
git checkout,git commit,git reset, and to execute a local Python script viatools/experiment_log.py add <results.tsv>(SKILL.md).
Audit Metadata