eval-harness
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill defines a 'Model-Based Grader' that uses the AI agent to evaluate code changes and open-ended outputs. This introduces an indirect prompt injection surface where the content being evaluated could contain instructions designed to manipulate the grader's outcome.
- Ingestion points: External data such as "code change" and "open-ended outputs" are processed by the
MODEL GRADER PROMPTdefined inSKILL.md. - Boundary markers: The provided templates do not use specific delimiters or instructions to treat the evaluated content as passive data, increasing the risk that embedded instructions might be followed by the agent.
- Capability inventory: The skill has access to powerful tools including
Bash,Write, andEdit, which could be misused if the agent's evaluation logic is compromised. - Sanitization: There is no evidence of sanitization, escaping, or validation of the input data before it is interpolated into the grader's prompt.
Audit Metadata