experiment-audit

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local project environment to perform its audit functions.
  • Ingestion points: Files matching patterns such as *eval*.py, *.json, *.csv, and *.yaml are scanned in SKILL.md (Step 1) and contents are potentially read by the reviewer.
  • Boundary markers: The workflow relies on natural language instructions to separate the executor's intent from the data being reviewed, but does not implement cryptographic or robust delimiter-based isolation.
  • Capability inventory: The skill is granted Bash(*), Read, Write, Edit, Grep, and Glob tools, along with access to specific MCP review tools (mcp__codex__codex).
  • Sanitization: There is no evidence of sanitization or filtering of the content within the identified files before they are passed to the reviewer backend.
  • [COMMAND_EXECUTION]: The skill utilizes Bash(*) and Grep to perform discovery of experiment artifacts within the user's workspace, which is standard behavior for a project auditing tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:07 PM
Security Audit — agent-trust-hub — experiment-audit