optimize
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill framework processes external workloads and evaluation feedback, which represents a surface for indirect prompt injection. This risk is managed through defined safety constraints and authority requirements.
- Ingestion points: External data is ingested through 'representative workloads' and 'judged outcomes' (SKILL.md, references/judged-outcomes.md).
- Boundary markers: The instructions mandate 'hard constraints' and 'acceptance constraints' (including security) before starting, along with blinding labels during evaluation.
- Capability inventory: The skill utilizes tools like
alaga,ko-skill, andseda-prto finalize and publish changes based on trial results. - Sanitization: Actions like installation, external disclosure, and destructive changes are subject to their own authority requirements.
- [SAFE]: No malicious patterns or security vulnerabilities were identified. The instructions emphasize best practices for controlled experimentation, including budget limits and the rejection of false improvements.
Audit Metadata