hypogenic
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external dataset text and model-generated hypotheses. It mitigates injection risks by treating all such text as untrusted data, applying strict schema validation, and redacting raw content in audit reports and inspections.
- Ingestion points:
scripts/audit_dataset.py(dataset JSON),scripts/inspect_outputs.py(hypothesis bank JSON), andscripts/evaluate_local.py(result JSON). - Boundary markers: The
SKILL.mdand example task configuration files include explicit instructions to treat all supplied text as quoted data and not as instructions. - Capability inventory: The bundled tools perform file I/O, hashing, and numeric analysis. They do not have the capability to execute instructions found within the data.
- Sanitization: The skill uses strict type-checking, length limits, and numeric bounds (e.g., node counts, document depth) to prevent malicious payloads from influencing agent behavior.
- [COMMAND_EXECUTION]: The skill uses
uvandpython3to run local, deterministic scripts for auditing and planning. These scripts do not interpolate untrusted text into shell commands or dynamically execute code. - [EXTERNAL_DOWNLOADS]: The skill references the
hypogenicpackage and officialChicagoHAIrepositories. It provides specific SHA-256 hashes for the package artifacts and immutable commit SHAs for datasets, ensuring supply chain integrity through verification. - [CREDENTIALS_UNSAFE]: The skill implements active detection for hardcoded secrets. It rejects configuration files containing common API key patterns or field names like
api_keyorsecret. It checks for the presence of environment variables using specialized helper functions that only return presence as a boolean without exposing the variable's value. - [SAFE]: The YAML parser in
scripts/_common.pyuses aSafeLoadersubclass and performs a manual token scan to reject aliases, anchors, and explicit tags, effectively mitigating YAML-based resource exhaustion or object injection attacks. This usage addresses the security concerns typically associated with standard YAML loading.
Audit Metadata