create-custom-grader
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection because it ingests untrusted external data—such as benchmarks, rubrics, and task YAML/JSON files—to generate executable grading logic.
- Ingestion points: Benchmark source files,
task.yaml,task.json, and rubric text are read from the target directory as specified inSKILL.md. - Boundary markers: Absent. The instructions do not provide explicit boundary markers or delimiters to separate untrusted user data from the generated code.
- Capability inventory: The skill generates executable
.pyand.shfiles and runs shell commands via theskillevaluatorCLI. - Sanitization: Absent. There is no guidance for validating or sanitizing user-provided rubric content before it is incorporated into the generated scoring logic.
- [COMMAND_EXECUTION]: The skill facilitates dynamic code execution by instructing the agent to scaffold and implement
grader.pyorgrader.shscripts, which are subsequently executed by theskillevaluatortool in a verifier context. This represents the generation of executable content from user-provided templates.
Audit Metadata