agent-eval
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs users to a third-party GitHub repository (
github.com/joaquinhuigomez/agent-eval) to download and install a CLI tool. This repository is not affiliated with the skill author or recognized trusted organizations. - [COMMAND_EXECUTION]: The instructions and workflow involve executing shell commands via the
agent-evaltool and running arbitrary judge commands (e.g.,pytest,npm run build) defined in YAML task files. - [INDIRECT_PROMPT_INJECTION]: The skill's architecture for processing task definitions presents a surface for indirect prompt injection as it executes instructions derived from external data files.
- Ingestion points: YAML task definition files located in the
tasks/directory, as described inSKILL.md. - Boundary markers: No specific boundary markers or instruction-ignoring delimiters are mentioned for the
promptorcommandfields. - Capability inventory: The skill uses
Bash,Read,Write, andEdittools, and executes shell commands specified in the configuration'sjudgecriteria. - Sanitization: There is no evidence of sanitization or filtering applied to the commands or prompts before they are executed or passed to the agent.
Audit Metadata