Security Audit Eval

Audit a third-party Inspect AI evaluation for security risks before running it locally. Decide whether the eval is safe by checking for malicious host-side code, externally-fetched files that aren't quality-controlled, sandbox-breakout instructions, weak sandbox configuration, supply-chain hazards, credential exposure, resource exhaustion, and provenance signals. Use when the user asks to audit / vet / security-review an eval repo (GitHub URL or local path), or asks "is it safe to run X". Do NOT use for assessing whether an eval *measures what it claims* (use eval-validity-review) or for general code-quality review (use eval-quality-workflow / code-quality-review-all).

UKGovernmentBEIS 6ac8ecc 17.9 KB Updated

File contents

ukgovernmentbeis/inspect_evals/tree/main/.claude/skills/security-audit-eval commit 6ac8ecc434

Frequently asked questions

npx skillmds@latest add ukgovernmentbeis/security-audit-eval