ml-model-evaluation

Warn

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill's reference directory contains an anomalous amount of repetitive and irrelevant filler content across files such as architecture-patterns.md, code-organization.md, and security-best-practices.md.
  • Evidence: These files contain approximately 1,200 sections of duplicated text regarding low-level kernel optimizations (e.g., io_uring, epoll_wait) that are technically unrelated to the stated purpose of machine learning model evaluation.
  • Ingestion Risk: The skill's workflow encourages the agent to consult these large reference files, which forces the ingestion of massive amounts of redundant data into the agent's active context window.
  • Impact: This data bloat significantly increases the risk of context exhaustion or displacement, potentially causing the agent to 'forget' its primary system instructions or user-defined security constraints in favor of the noise introduced by the filler data.
  • Adversarial Pattern: The inclusion of Technical-sounding but functionally useless content split into hundreds of artificial 'Staff+ Engineer' sections is a known technique for bypassing instruction-following performance or hiding malicious signals within high-entropy noise.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 8, 2026, 12:24 PM
Security Audit — agent-trust-hub — ml-model-evaluation