create-custom-grader

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection because it ingests untrusted external data—such as benchmarks, rubrics, and task YAML/JSON files—to generate executable grading logic.
  • Ingestion points: Benchmark source files, task.yaml, task.json, and rubric text are read from the target directory as specified in SKILL.md.
  • Boundary markers: Absent. The instructions do not provide explicit boundary markers or delimiters to separate untrusted user data from the generated code.
  • Capability inventory: The skill generates executable .py and .sh files and runs shell commands via the skillevaluator CLI.
  • Sanitization: Absent. There is no guidance for validating or sanitizing user-provided rubric content before it is incorporated into the generated scoring logic.
  • [COMMAND_EXECUTION]: The skill facilitates dynamic code execution by instructing the agent to scaffold and implement grader.py or grader.sh scripts, which are subsequently executed by the skillevaluator tool in a verifier context. This represents the generation of executable content from user-provided templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 12:40 PM
Security Audit — agent-trust-hub — create-custom-grader