ml-model-evaluation
Warn
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill's reference directory contains an anomalous amount of repetitive and irrelevant filler content across files such as
architecture-patterns.md,code-organization.md, andsecurity-best-practices.md. - Evidence: These files contain approximately 1,200 sections of duplicated text regarding low-level kernel optimizations (e.g.,
io_uring,epoll_wait) that are technically unrelated to the stated purpose of machine learning model evaluation. - Ingestion Risk: The skill's workflow encourages the agent to consult these large reference files, which forces the ingestion of massive amounts of redundant data into the agent's active context window.
- Impact: This data bloat significantly increases the risk of context exhaustion or displacement, potentially causing the agent to 'forget' its primary system instructions or user-defined security constraints in favor of the noise introduced by the filler data.
- Adversarial Pattern: The inclusion of Technical-sounding but functionally useless content split into hundreds of artificial 'Staff+ Engineer' sections is a known technique for bypassing instruction-following performance or hiding malicious signals within high-entropy noise.
Audit Metadata