experiment-bridge

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes experiment scripts and shell commands using the Bash tool and specialized deployment commands like /run-experiment and /experiment-queue.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates downloading external codebases through the git clone command when the BASE_REPO parameter is provided by the user.
  • [DYNAMIC_EXECUTION]: The workflow involves generating new Python and shell scripts based on experimental plans and executing them. It includes an automated debugging loop that attempts to patch and re-run code that fails sanity checks (up to 4 attempts).
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted data from multiple project files and cloned repositories to guide code generation. 1. Ingestion points: EXPERIMENT_PLAN.md, FINAL_PROPOSAL.md, and the cloned BASE_REPO. 2. Boundary markers: The skill uses section headers in prompts to delimit content for secondary model review. 3. Capability inventory: Employs Bash, Write, and Edit tools. 4. Sanitization: No evidence of input filtering or validation for the data used in prompt construction.
  • [REMOTE_CODE_EXECUTION]: The skill implements a feature to clone a user-specified repository and execute scripts within it, which constitutes a remote code execution vector if the source repository is malicious.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:07 PM
Security Audit — agent-trust-hub — experiment-bridge