cuopt-skill-evolution
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions in
SKILL.mddirect the agent to execute local validation scripts, such as./ci/utils/validate_skills.shand./ci/test_skills_assets.sh, and run the cuOpt solver locally viasolution.pyto confirm the validity of new learnings. These operations are performed within a controlled validation workflow.\n- [DYNAMIC_EXECUTION]: The agent is authorized to generate new Python code assets (assets/*.py) and Markdown skill updates based on identified patterns. The skill explicitly prohibits the use of unsafe functions likeeval()orexec()with untrusted user input in these generated examples.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user corrections and interaction patterns to derive new rules, which constitutes an indirect injection surface.\n - Ingestion points:
SKILL.md(instructions to evaluate user corrections and behavior during problem-solving).\n - Boundary markers: Present; the skill uses a structured 'Proposal format' for all updates, ensuring changes are clearly presented for user review.\n
- Capability inventory:
SKILL.md(describes execution of validation scripts and writing to skill directories and code assets).\n - Sanitization: Present; the skill includes explicit rules to strip user-specific data, avoid safety-weakening proposals, and require human approval before any change is persisted.
Audit Metadata