agent-eval
Warn
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill refers users to an external repository (github.com/joaquinhuigomez/agent-eval) for installation. This source is not from a well-known or trusted organization, representing a potential supply-chain risk if the external tool is malicious.
- [COMMAND_EXECUTION]: The evaluation workflow relies on executing arbitrary shell commands specified within YAML task configurations (e.g., using the
pytestornpm run buildcommands in the judge block). This creates a surface where malicious commands could be executed if configuration files are sourced from untrusted locations. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests task definitions from YAML files that include natural language prompts and executable commands without explicit sanitization.
- Ingestion points: YAML task definition files within the
tasks/directory. - Boundary markers: None identified in the documentation or example YAML structures to separate instructions from untrusted data.
- Capability inventory: The agent is granted
Bash,Read,Write, andEdittools which can be leveraged by injected instructions. - Sanitization: There is no evidence of input validation or command escaping before the commands are passed to the shell.
Audit Metadata