experiment-craft
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides standard research methodology and debugging workflows. No evidence of credential exposure, data exfiltration, or malicious commands was found.
- [INDIRECT_PROMPT_INJECTION]: The skill's architecture presents a vulnerability surface for indirect prompt injection.
- Ingestion points: The agent gathers failure cases, results, and qualitative observations from user-provided logs and the research environment.
- Boundary markers: The instructions lack explicit boundary delimiters to prevent the agent from following instructions embedded within external experimental data.
- Capability inventory: The agent is equipped with
write_file,edit_file,read_file, andexecutetools. - Sanitization: The skill does not implement or recommend sanitization or validation of data before it is processed by the agent.
Audit Metadata