shinka-run

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the shinka_run and shinka_models CLI tools to execute program evolution tasks and check model configurations. These tools are provided by the vendor, SakanaAI, for the intended purpose of the skill.- [DYNAMIC_EXECUTION]: The skill is designed to run the ShinkaEvolve framework, which generates and evaluates program mutations. This involves the dynamic execution of mutated code artifacts at runtime to identify performance optimizations.- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from evaluate.py and initial.<ext> files, as well as user feedback used to construct task system messages. 1. Ingestion points: File contents from the task directory and user-provided feedback for the evo.task_sys_msg parameter. 2. Boundary markers: No explicit boundary markers or ignore instructions warnings are specified for the ingested content. 3. Capability inventory: The skill can execute shell commands via the shinka_run CLI. 4. Sanitization: The instructions do not specify any sanitization or validation of the ingested content before it is processed by the evolutionary runner.- [EXTERNAL_DOWNLOADS]: The skill documentation references the official ShinkaEvolve repository hosted at https://github.com/SakanaAI/ShinkaEvolve. This is a vendor-owned resource.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:48 PM
Security Audit — agent-trust-hub — shinka-run