wjs-evaling-voicedrop-prompts
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Node.js scripts (
eval/run-eval.mjs) and verification tests (npm test) within the user's project directory (~/code/jianshuo.dev/agent). These operations are consistent with the tool's purpose as a development evaluation harness. - [PROMPT_INJECTION]: The evaluation process involves a subagent judge that processes content generated by candidate prompts. This creates a surface for indirect prompt injection, as the subagent could potentially be influenced by instructions embedded within the generated text it is tasked to evaluate.
Audit Metadata