evolving-ai-agents
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The A-Evolve framework architecture creates a vulnerability surface for indirect prompt injection. The system ingests untrusted data from benchmark tasks and resulting agent trajectories, which are then analyzed by an evolution engine (LLM) to guide mutations of the agent's system prompt and skill library.
- Ingestion points: External task inputs and feedback details provided by benchmark adapters as described in references/api.md and references/tutorials.md.
- Boundary markers: The documentation outlines the use of markdown headers and YAML frontmatter for structuring evolved files (e.g., SKILL.md), but does not specify robust sanitization or instruction-isolation techniques for untrusted benchmark content when processed by the evolution engine.
- Capability inventory: The evolution engine (specifically the default AEvolveEngine) is documented to have full bash tool access and file-writing capabilities to modify the agent's workspace, including critical logic files like prompts/system.md and scripts in the skills/ directory (references/architecture.md).
- Sanitization: The documentation does not describe explicit sanitization, filtering, or validation mechanisms to prevent instructions embedded in task data from influencing the evolver's file-system mutations.
- [DYNAMIC_EXECUTION]: The framework is built around the principle of runtime code mutation and execution. The evolution loop involves an LLM (the evolver) generating or refining agent code and configuration at runtime, which is then reloaded and executed by the agent in subsequent cycles (references/architecture.md, references/api.md).
- [COMMAND_EXECUTION]: The evolution process utilizes a mechanism for arbitrary command execution on the host environment. The default AEvolveEngine provides the evolution LLM with access to bash tools to perform direct workspace modifications and other shell operations necessary for agent improvement (references/README.md, references/architecture.md).
- [EXTERNAL_DOWNLOADS]: The documentation provides instructions for installing the A-Evolve framework and its dependencies from external repositories and registries. This includes cloning from GitHub (github.com/A-EVO-Lab/a-evolve.git) and installing packages via PyPI (pip install a-evolve). These resources are managed by the skill's vendor.
Audit Metadata