ab-testing
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing statsmodels and scipy from PyPI, which are well-known and reputable statistical libraries.
- [COMMAND_EXECUTION]: Includes a shell script (scripts/verify.sh) that uses standard utilities like find and grep to inspect project files.
- [DYNAMIC_EXECUTION]: The verify.sh script locates and executes Python scripts within the project to verify statistical sizing and analysis results.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided experimental hypotheses and metrics, creating a potential surface for injection. 1. Ingestion points: User prompts regarding experiment design and metrics. 2. Boundary markers: The instructions lack explicit delimiters or safety warnings for processing external data. 3. Capability inventory: Python script generation and execution via the verify.sh utility. 4. Sanitization: No sanitization is performed on user-provided data before it is interpolated into scripts.
Audit Metadata