eval-agents
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow where content from project files (AGENTS.md, scenarios, and source code) is interpolated directly into prompts for subagents during evaluation and stress-testing phases. This creates a surface for indirect prompt injection if the project documentation being evaluated contains instructions designed to manipulate the subagent's behavior.
- Ingestion points: The skill reads
AGENTS.md,docs/agents-eval-scenarios.md,docs/eval-session-trace.md, and multiple source files listed in the 'Exploration Directives' (e.g.,src/cli/commands/task.ts,src/schema/spec.ts). - Boundary markers: The skill uses basic separators (
---) and placeholder tags (e.g.,<paste AGENTS.md content here>) to delimit external content, but does not provide explicit instructions to ignore potentially conflicting commands within that content. - Capability inventory: The skill is capable of spawning subagents and reading a wide variety of files across the project repository.
- Sanitization: No explicit sanitization or escaping of the ingested file content is performed before interpolation into subagent prompts.
Audit Metadata