experiment-bridge
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes experiment scripts and shell commands using the
Bashtool and specialized deployment commands like/run-experimentand/experiment-queue. - [EXTERNAL_DOWNLOADS]: The skill facilitates downloading external codebases through the
git clonecommand when theBASE_REPOparameter is provided by the user. - [DYNAMIC_EXECUTION]: The workflow involves generating new Python and shell scripts based on experimental plans and executing them. It includes an automated debugging loop that attempts to patch and re-run code that fails sanity checks (up to 4 attempts).
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted data from multiple project files and cloned repositories to guide code generation. 1. Ingestion points:
EXPERIMENT_PLAN.md,FINAL_PROPOSAL.md, and the clonedBASE_REPO. 2. Boundary markers: The skill uses section headers in prompts to delimit content for secondary model review. 3. Capability inventory: EmploysBash,Write, andEdittools. 4. Sanitization: No evidence of input filtering or validation for the data used in prompt construction. - [REMOTE_CODE_EXECUTION]: The skill implements a feature to clone a user-specified repository and execute scripts within it, which constitutes a remote code execution vector if the source repository is malicious.
Audit Metadata