darwin
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from various repository sources to perform its analysis and evolution tasks.
- Ingestion points: Data is collected from
git logoutput, file structure listings,pyproject.toml,package.json, and agent journals located in the.agents/directory (reference/signal-collection.md). - Boundary markers: The skill uses instructional constraints such as "Propose, never force" and "Integrate, don't duplicate" in
SKILL.md, and references a "review-before-merge default" for pattern synthesis inreference/subsystems.md. - Capability inventory: The skill has the ability to write to
.agents/ECOSYSTEM.mdand.agents/darwin.md, and it generates evolution proposals that influence the behavior and routing of other agents (e.g.,Architect,Nexus). - Sanitization: There is no explicit evidence of sanitization, validation, or escaping of the ingested content (e.g., commit messages or journal entries) before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill's reference documentation defines specific shell commands that the agent is expected to execute to collect project signals.
- Evidence:
reference/signal-collection.mdlists commands such asgit log --since="30 days" --oneline | wc -l,git shortlog -sn --since="90 days",git log --stat, andfind . -type f | wc -l. While standard, these represent a direct command execution interface with the host environment. - [METADATA_POISONING]: The skill incorporates a significant amount of deceptive or fictitious metadata regarding the current time and industry state.
- Evidence: Throughout the reference files (e.g.,
reference/assessment-models.md,reference/evolution-actions.md), the skill cites a "2026-05 baseline" and references industry events, research papers, and product releases with future dates (e.g., May 2026). This creates a misleading context for the agent's operations and the validity of its internal benchmarks.
Audit Metadata