wjs-evaling-voicedrop-prompts

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Node.js scripts (eval/run-eval.mjs) and verification tests (npm test) within the user's project directory (~/code/jianshuo.dev/agent). These operations are consistent with the tool's purpose as a development evaluation harness.
  • [PROMPT_INJECTION]: The evaluation process involves a subagent judge that processes content generated by candidate prompts. This creates a surface for indirect prompt injection, as the subagent could potentially be influenced by instructions embedded within the generated text it is tasked to evaluate.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 07:32 AM
Security Audit — agent-trust-hub — wjs-evaling-voicedrop-prompts