ai-eval-playbook

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches live documentation from eval.playbook.org.ai to ensure use of the most current framework version and references a repository hosted by the IDinsight organization on GitHub.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it processes data from an external website to generate responses.
  • Ingestion points: Data is retrieved from the eval.playbook.org.ai domain using web fetching and indexing tools.
  • Boundary markers: The instructions lack specific delimiters or directive warnings to ignore potential malicious instructions embedded within the fetched external content.
  • Capability inventory: The agent possesses the ability to read local workspace files (mel_wiki/wiki/frameworks/) and utilize network tools for information retrieval.
  • Sanitization: There is no evidence of content sanitization or verification performed on the retrieved remote data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 03:17 PM
Security Audit — agent-trust-hub — ai-eval-playbook