eval
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill implements an evaluation loop that processes responses from an external AI Gateway, exposing the analyzing agent to potential indirect prompt injection (Category 8).
- Ingestion points: Untrusted data enters the agent context via network responses in
runner.ts(stored in JSON files) and is subsequently loaded for analysis as described inSKILL.md. - Boundary markers: The skill does not employ specific delimiters or isolation markers when presenting agent outputs within its JSON and Markdown reports, making it difficult for a judging AI to distinguish between instructions and data.
- Capability inventory: The skill environment possesses capabilities such as shell command execution (
gitviaBun.spawninrunner.ts), network communication (fetchinrunner.ts), and file system writes (writeFileinrunner.tsandreporter.ts). - Sanitization: There is no evidence of sanitization or content filtering applied to the responses fetched from the AI Gateway before they are interpreted by the agent or included in the final markdown reports.
Audit Metadata