arbor

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill inherently operates on external artifacts (code, configurations, or prompts) and executes user-defined evaluation commands (E_dev and E_test). This functional requirement creates a surface for indirect prompt injection if the material being optimized contains malicious instructions. However, the skill provides specific guidance on using isolated git worktrees for executors to mitigate system-level risks.
    • Ingestion points: The material (source artifact) and the outputs of evaluation commands.
    • Boundary markers: Not explicitly implemented in the prompt logic beyond task-tuple definitions.
    • Capability inventory: Bash (for running evaluators) and Agent (for subagent task execution).
    • Sanitization: The skill relies on process isolation (worktrees) rather than content filtering.
  • [EXTERNAL_DOWNLOADS]: The documentation references the official GitHub repository for the upstream Arbor tool (github.com/RUC-NLPIR/Arbor) for users who prefer the standalone CLI. This is an informative reference to a legitimate research project and does not involve automated execution of untrusted remote code.
  • [COMMAND_EXECUTION]: The scripts/tree.py utility is a local state manager that performs safe file I/O operations (JSON) to track the hypothesis tree. It does not utilize dangerous functions like eval() or os.system().
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — arbor