cuopt-skill-evolution

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions in SKILL.md direct the agent to execute local validation scripts, such as ./ci/utils/validate_skills.sh and ./ci/test_skills_assets.sh, and run the cuOpt solver locally via solution.py to confirm the validity of new learnings. These operations are performed within a controlled validation workflow.\n- [DYNAMIC_EXECUTION]: The agent is authorized to generate new Python code assets (assets/*.py) and Markdown skill updates based on identified patterns. The skill explicitly prohibits the use of unsafe functions like eval() or exec() with untrusted user input in these generated examples.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user corrections and interaction patterns to derive new rules, which constitutes an indirect injection surface.\n
  • Ingestion points: SKILL.md (instructions to evaluate user corrections and behavior during problem-solving).\n
  • Boundary markers: Present; the skill uses a structured 'Proposal format' for all updates, ensuring changes are clearly presented for user review.\n
  • Capability inventory: SKILL.md (describes execution of validation scripts and writing to skill directories and code assets).\n
  • Sanitization: Present; the skill includes explicit rules to strip user-specific data, avoid safety-weakening proposals, and require human approval before any change is persisted.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 11:41 AM
Security Audit — agent-trust-hub — cuopt-skill-evolution