night-market-model-and-harness-updates
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted external data such as model release notes and cards to drive automated updates across the repository.
- Ingestion points: External content is fetched using
WebSearch,WebFetch, or thetome:researchtool inmodules/research-protocol.md. - Boundary markers: The skill distinguishes these inputs as "external captures" and "other people's text" in
SKILL.mdandmodules/asset-sweep.md, though no technical delimiters are defined for processing. - Capability inventory: The skill can modify repository files (agents, skills, commands, hooks) and update the central ledger via local script execution (
python3,rg,pytest). - Sanitization: Findings require source URLs and consultation of specific authoritative documents, acting as manual validation, but no automated sanitization of fetched data is implemented.
- [DYNAMIC_EXECUTION]: The skill provides Python code templates for the agent to use when updating the internal maintenance ledger.
- Evidence:
modules/verification.mdincludes a Python script template that imports local scripts and mutates the JSON ledger. - [COMMAND_EXECUTION]: The workflow relies on local scripts and tools for validation, drift detection, and file identification.
- Evidence:
SKILL.mdand modules invokepython3 scripts/check_upstream_drift.py,python3 scripts/check_agent_model_matrix.py, andrg(ripgrep).
Audit Metadata