arize-prompt-optimization

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a data-driven optimization loop that ingests external trace data and evaluation explanations from spans.json and runs.json. This data is directly interpolated into a 'meta-prompt' used to redesign LLM instructions.
  • Ingestion points: Data enters the context via ax spans export and ax datasets export in Phase 1 and 2.
  • Boundary markers: The meta-prompt uses explicit headers like PERFORMANCE DATA and ORIGINAL BASELINE PROMPT, which provide some structural delimitation.
  • Capability inventory: The skill uses ax CLI commands for network operations and jq for file processing.
  • Sanitization: There is no evidence of sanitization for the content of the trace messages or evaluation explanations before they are included in the optimization prompt, allowing potentially malicious production data to reach the LLM's instruction-tuning phase.
  • [PERSISTENCE]: The skill's documentation in references/ax-profiles.md provides instructions for persisting the ARIZE_SPACE environment variable by modifying shell configuration files such as ~/.zshrc or ~/.bashrc. While this is presented as a standard user-driven configuration step for CLI tools, it involves modifying persistent shell startup scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:55 AM
Security Audit — agent-trust-hub — arize-prompt-optimization