agent-eval

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs users to a third-party GitHub repository (github.com/joaquinhuigomez/agent-eval) to download and install a CLI tool. This repository is not affiliated with the skill author or recognized trusted organizations.
  • [COMMAND_EXECUTION]: The instructions and workflow involve executing shell commands via the agent-eval tool and running arbitrary judge commands (e.g., pytest, npm run build) defined in YAML task files.
  • [INDIRECT_PROMPT_INJECTION]: The skill's architecture for processing task definitions presents a surface for indirect prompt injection as it executes instructions derived from external data files.
  • Ingestion points: YAML task definition files located in the tasks/ directory, as described in SKILL.md.
  • Boundary markers: No specific boundary markers or instruction-ignoring delimiters are mentioned for the prompt or command fields.
  • Capability inventory: The skill uses Bash, Read, Write, and Edit tools, and executes shell commands specified in the configuration's judge criteria.
  • Sanitization: There is no evidence of sanitization or filtering applied to the commands or prompts before they are executed or passed to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — agent-eval