experiment

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes and iterates on external artifacts and configuration files, creating a surface for potential instruction injection.
  • Ingestion points: The agent reads the experiment definition from CARD.md and the target content from a "mutable surface" file (SKILL.md).
  • Boundary markers: The skill references an "autonomy gate" to verify the safety of the environment, but does not define specific technical delimiters or instruction isolation for the content being optimized (SKILL.md).
  • Capability inventory: The skill performs file writes (editing the mutable surface), version control operations (git checkout, git commit, git reset), and executes a local script (tools/experiment_log.py) (SKILL.md).
  • Sanitization: There are no explicit instructions for sanitizing or escaping the content of the artifacts being modified (SKILL.md).
  • [DYNAMIC_EXECUTION]: The skill is designed to have the agent iteratively modify a "mutable surface" (which may be code) and then execute a "read-only harness" to evaluate the changes.
  • Evidence: The workflow involves editing a target file and running it via a harness to generate a results.tsv log (SKILL.md).
  • [COMMAND_EXECUTION]: The skill utilizes shell commands to manage the experimentation lifecycle and logging.
  • Evidence: The instructions explicitly direct the agent to use git checkout, git commit, git reset, and to execute a local Python script via tools/experiment_log.py add <results.tsv> (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 07:20 PM
Security Audit — agent-trust-hub — experiment