arbor
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill inherently operates on external artifacts (code, configurations, or prompts) and executes user-defined evaluation commands (E_dev and E_test). This functional requirement creates a surface for indirect prompt injection if the material being optimized contains malicious instructions. However, the skill provides specific guidance on using isolated git worktrees for executors to mitigate system-level risks.
- Ingestion points: The
material(source artifact) and the outputs of evaluation commands. - Boundary markers: Not explicitly implemented in the prompt logic beyond task-tuple definitions.
- Capability inventory:
Bash(for running evaluators) andAgent(for subagent task execution). - Sanitization: The skill relies on process isolation (worktrees) rather than content filtering.
- Ingestion points: The
- [EXTERNAL_DOWNLOADS]: The documentation references the official GitHub repository for the upstream Arbor tool (
github.com/RUC-NLPIR/Arbor) for users who prefer the standalone CLI. This is an informative reference to a legitimate research project and does not involve automated execution of untrusted remote code. - [COMMAND_EXECUTION]: The
scripts/tree.pyutility is a local state manager that performs safe file I/O operations (JSON) to track the hypothesis tree. It does not utilize dangerous functions likeeval()oros.system().
Audit Metadata