experiment-audit
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local project environment to perform its audit functions.
- Ingestion points: Files matching patterns such as
*eval*.py,*.json,*.csv, and*.yamlare scanned inSKILL.md(Step 1) and contents are potentially read by the reviewer. - Boundary markers: The workflow relies on natural language instructions to separate the executor's intent from the data being reviewed, but does not implement cryptographic or robust delimiter-based isolation.
- Capability inventory: The skill is granted
Bash(*),Read,Write,Edit,Grep, andGlobtools, along with access to specific MCP review tools (mcp__codex__codex). - Sanitization: There is no evidence of sanitization or filtering of the content within the identified files before they are passed to the reviewer backend.
- [COMMAND_EXECUTION]: The skill utilizes
Bash(*)andGrepto perform discovery of experiment artifacts within the user's workspace, which is standard behavior for a project auditing tool.
Audit Metadata