nat-optimization
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external evaluation datasets (e.g.,
eval_dataset.json) to optimize AI agent parameters and prompts. - Ingestion points: Untrusted data enters the agent context via the
eval.general.datasetconfiguration field inworkflow.yaml(referenced inreferences/complete-config-example.md). - Boundary markers: The provided documentation does not define specific delimiters or instructions for the agent to ignore malicious content potentially embedded within the evaluation datasets.
- Capability inventory: The
nat optimizeprocess executes workflows which include LLM generation and potentially tool execution across multiple trials (as described inreferences/choosing-parameters.md). - Sanitization: No evidence of sanitization, filtering, or validation of the dataset content is present in the provided configuration files or reference guides.
Audit Metadata