bat-story-eval

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the uv Python runner to execute local testing and verification scripts against Home Assistant instances.
  • [COMMAND_EXECUTION]: It manages isolated test environments using Docker, specifically targeting official images from the Home Assistant container registry (ghcr.io).
  • [DATA_EXPOSURE_AND_EXFILTRATION]: Data access is confined to a specific development worktree and temporary file storage for generated test configurations, without evidence of external exfiltration.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes local YAML test definitions and source code changes, implementing a structured evaluation protocol to assess and compare agent responses across different models and versions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 03:50 PM
Security Audit — agent-trust-hub — bat-story-eval