ml-generative-diffcsp

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external data from a JSON file in scripts/batch_generate.py. This represents an indirect prompt injection surface where maliciously crafted technical data could attempt to influence the agent's behavior.
  • Ingestion points: The args.json_file argument in scripts/batch_generate.py reads user-provided JSON content for batch processing.
  • Boundary markers: No delimiters or specific instructions to ignore embedded commands are present in the provided scripts to wrap the external data.
  • Capability inventory: The skill is focused on machine learning inference for materials science; no high-risk capabilities like arbitrary shell execution, unauthorized file system modification, or network exfiltration were detected in the provided scripts.
  • Sanitization: No explicit validation or sanitization logic for the content of the JSON fields was found in the calling script before data is passed to the underlying wrapper.
  • [SAFE]: The scripts scripts/batch_generate.py and scripts/unconditional_generate.py contain hardcoded environment variables (e.g., os.environ.setdefault("PROJECT_ROOT", "/home/bdeng/projects/DiffCSP-PP")) and path manipulations (relative pathing via sys.path.insert) that reflect the author's local research environment. These configurations do not pose a security risk, though they may impact the portability of the skill for other users.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 04:48 PM