simmer-judge
Pass
Audited by Gen Agent Trust Hub on Mar 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs the agent to perform external research (reading documentation, searching for techniques) when optimization plateaus. This involves fetching content from external domains as part of the intended researcher workflow.
- [PROMPT_INJECTION]: The agent processes untrusted external data from candidate artifacts and evaluator logs, which creates a surface for indirect prompt injection. Ingestion points: 'Current candidate' artifact text and 'Evaluator output' in SKILL.md. Boundary markers: No explicit delimiters or instructions to treat input as non-executable data are provided. Capability inventory: The skill produces 'ASI' instructions that directly influence the actions of a downstream generator agent. Sanitization: No validation or sanitization of the input artifact content is specified.
Audit Metadata