earos-rubric
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill focuses on assisting architects in defining structured evaluation criteria. It includes clear documentation and examples (references/examples.md) to ensure correct usage and output quality.
- [INDIRECT_PROMPT_INJECTION]: The skill features a 'Distributed path' (Phase 3D) that ingests user-provided reference materials and interpolates them into prompts for sub-agents to analyze. This creates a surface area for indirect prompt injection where malicious instructions inside architecture documents could attempt to influence the rubric's criteria. However, the risk is mitigated by the use of clear boundary markers and the requirement for final human review of the generated rubric. * Ingestion points: Reference materials and file paths provided by the user in Phase 2.5. * Boundary markers: Sub-agent prompts utilize specific headers like '## Context brief' and '## Your assigned material' to delimit untrusted content. * Capability inventory: Reading local files and spawning sub-agents via the platform's 'Agent tool'. * Sanitization: The skill does not explicitly sanitize the source text for instructions, but it includes an interactive consolidation phase where the user reviews and approves every dimension and criterion.
Audit Metadata