arize-prompt-optimization
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a data-driven optimization loop that ingests external trace data and evaluation explanations from
spans.jsonandruns.json. This data is directly interpolated into a 'meta-prompt' used to redesign LLM instructions. - Ingestion points: Data enters the context via
ax spans exportandax datasets exportin Phase 1 and 2. - Boundary markers: The meta-prompt uses explicit headers like
PERFORMANCE DATAandORIGINAL BASELINE PROMPT, which provide some structural delimitation. - Capability inventory: The skill uses
axCLI commands for network operations andjqfor file processing. - Sanitization: There is no evidence of sanitization for the content of the trace messages or evaluation explanations before they are included in the optimization prompt, allowing potentially malicious production data to reach the LLM's instruction-tuning phase.
- [PERSISTENCE]: The skill's documentation in
references/ax-profiles.mdprovides instructions for persisting theARIZE_SPACEenvironment variable by modifying shell configuration files such as~/.zshrcor~/.bashrc. While this is presented as a standard user-driven configuration step for CLI tools, it involves modifying persistent shell startup scripts.
Audit Metadata