investigating-eval-results
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads evaluation data from Google Cloud Storage (
gs://guidance-evals/). Google is a recognized trusted organization, and this operation is an expected part of the diagnostic workflow.\n- [COMMAND_EXECUTION]: Executes platform-specific CLI toolsgd evalandgd devto run tests and calibrate results. It also usesgcloudto transfer remote results. These commands are within the scope of developer operations.\n- [PROMPT_INJECTION]: The skill processes untrusted input from evaluation trajectories and task files to update guidance and grading logic.\n - Ingestion points: Files in
harness/results/andguides/(e.g.,session-*.json,task.md).\n - Boundary markers: None identified in instructions.\n
- Capability inventory: File system writes to code files (
grader.ts) and shell command execution (gd).\n - Sanitization: None identified.\n
- Context: While this represents an attack surface (Category 8), the behavior is the primary intended function of an evaluation debugging skill and does not attempt to bypass agent safety filters.\n- [SAFE]: The skill's logic focuses on achieving 100% pass rates for agent tasks and explicitly restricts modification of underlying platform infrastructure, emphasizing a safe operational boundary.
Audit Metadata