eval-agents

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow where content from project files (AGENTS.md, scenarios, and source code) is interpolated directly into prompts for subagents during evaluation and stress-testing phases. This creates a surface for indirect prompt injection if the project documentation being evaluated contains instructions designed to manipulate the subagent's behavior.
  • Ingestion points: The skill reads AGENTS.md, docs/agents-eval-scenarios.md, docs/eval-session-trace.md, and multiple source files listed in the 'Exploration Directives' (e.g., src/cli/commands/task.ts, src/schema/spec.ts).
  • Boundary markers: The skill uses basic separators (---) and placeholder tags (e.g., <paste AGENTS.md content here>) to delimit external content, but does not provide explicit instructions to ignore potentially conflicting commands within that content.
  • Capability inventory: The skill is capable of spawning subagents and reading a wide variety of files across the project repository.
  • Sanitization: No explicit sanitization or escaping of the ingested file content is performed before interpolation into subagent prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 10:55 PM
Security Audit — agent-trust-hub — eval-agents