prompt-benchmark

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill utilizes the JavaScript Function constructor to evaluate arithmetic results produced by the AI model in the Game of 24 benchmark.
  • Evidence: The function evaluateExpression in SKILL.md contains const result = Function("\"use strict\"; return (${sanitized})")();.
  • While the code includes a sanitization step using expr.replace(/[^0-9+\-*/().]/g, ''), the use of dynamic execution for content sourced from model outputs is a risky implementation pattern.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data in the form of AI model responses across several benchmarks (MATH, GSM8K, Game of 24).
  • Ingestion points: The runBenchmark function in SKILL.md collects responses from a generateFn and passes them to evaluators like evaluateGSM8K and evaluateMATH.
  • Boundary markers: The prompt templates (e.g., cotPrompt, metaPromptGame24) do not use clear delimiters or instructions to prevent the agent from obeying instructions that might be embedded within the benchmark problems themselves.
  • Capability inventory: The skill has the ability to execute code (via Function) and manipulate string data based on these untrusted inputs.
  • Sanitization: While basic arithmetic characters are whitelisted for the math evaluator, there is no general sanitization or escaping of the model-generated responses before they are processed by the evaluation logic.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 08:04 PM
Security Audit — agent-trust-hub — prompt-benchmark