eval-harness

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a 'Model-Based Grader' that uses the AI agent to evaluate code changes and open-ended outputs. This introduces an indirect prompt injection surface where the content being evaluated could contain instructions designed to manipulate the grader's outcome.
  • Ingestion points: External data such as "code change" and "open-ended outputs" are processed by the MODEL GRADER PROMPT defined in SKILL.md.
  • Boundary markers: The provided templates do not use specific delimiters or instructions to treat the evaluated content as passive data, increasing the risk that embedded instructions might be followed by the agent.
  • Capability inventory: The skill has access to powerful tools including Bash, Write, and Edit, which could be misused if the agent's evaluation logic is compromised.
  • Sanitization: There is no evidence of sanitization, escaping, or validation of the input data before it is interpolated into the grader's prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 01:13 PM