skills/simota/agent-skills/experiment/Gen Agent Trust Hub

experiment

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides extensive documentation and guidance on statistical methods for experimentation. All code examples (TypeScript, SQL) are standard implementations of statistical tests (Z-test, Thompson Sampling, mSPRT, CUPED) and do not contain malicious payloads or unsafe dynamic execution patterns.
  • [SAFE]: The skill references established technology companies and services including OpenAI (Statsig), Datadog (Eppo), Spotify, LaunchDarkly, GrowthBook, PostHog, Microsoft, Uber, Airbnb, and DoorDash. These references are documented neutrally and provide legitimate technical context for experimentation platforms and methodologies.
  • [SAFE]: No evidence of prompt injection, obfuscation, or unauthorized data access was found. The instructions focus strictly on rigorous scientific experimentation and data integrity checks (e.g., SRM detection).
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface for indirect prompt injection as it processes experiment results and traffic data for statistical analysis. However, given the context of processing numerical counts and metrics, the risk is negligible and managed by standard agent guardrails. No specific malicious interpolation was detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:48 PM
Security Audit — agent-trust-hub — experiment