# eval-integrity

Audit an LLM evaluation or benchmark repo for integrity and credibility practices. Use when asked to "audit my benchmark," "is my eval trustworthy," "check my leaderboard for contamination," "review this benchmark's methodology," or "what would a reviewer attack in my eval." Greps the target repo fo

- **Type:** Agent Skill
- **Trust:** 10/100 (F), scored on the remote rubric — the security scan did not complete, so the security half is unavailable. This is a coverage gap, not a clean result and not a finding.
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.0.0
- **Author:** conorbronsdon
- **License:** MIT
- **Source:** https://github.com/conorbronsdon/agent-skills/tree/main/eval-integrity

## Trust

10/100 (F), scored on the remote rubric — the security scan did not complete, so the security half is unavailable. This is a coverage gap, not a clean result and not a finding.
- Publisher verified: no
- Install scripts: not scanned
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 11 days

## Security scan

- **Status:** failed
- **Scanned:** 2026-09-24T11:04:16.478Z
- **Version scanned:** unknown
- **CVEs:** none found by OSV at scan time

## Install

This is an Agent Skill — a prompt, not an MCP server, so there is no client config to generate. Fetch it with forge_get_skill and install it with forge_add_skill.

## Blast radius

Contained blast radius — runs as a prompt.
- Floor 4, ceiling 4 (tier: contained)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/eval-integrity
- Install plan: https://forgeregistry.com/api/v1/packages/eval-integrity/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/eval-integrity
- HTML page: https://forgeregistry.com/registry/eval-integrity
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
