eval-creator-ci
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill implements a verification method that executes arbitrary shell commands read directly from markdown files in the .evals/cases/ directory.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from repository files and GitHub Action artifacts that can contain malicious instructions.
- Ingestion points: Evaluation cases from .evals/cases/ and gap reports from learning-aggregator-ci artifacts.
- Boundary markers: None identified to delimit instructions from data in evaluation case files.
- Capability inventory: Shell command execution, pattern matching (grep), and file system write access to the .evals/ directory.
- Sanitization: No evidence of sanitization or validation of commands extracted from metadata before execution.
- [DYNAMIC_EXECUTION]: Verification logic and commands are dynamically determined and executed at runtime based on the contents of external evaluation case files.
- [EXTERNAL_DOWNLOADS]: The skill instructions reference downloading the gh-aw extension from GitHub's official repository.
Audit Metadata