Skip to content
Back to skills

Agent Evaluation

ASecurity

Evaluate prompt, model, retrieval, and agent changes with repeated graded trials.

  • 10 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 23, 2026
ai-agentsrustgogitdatabasesecuritydocumentation

Works with

  • cli

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 6, 2026

npx -y skills add fmind/dot --skill agent-evaluation --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Agent Evaluation?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Agent Evaluation
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/fmind-agent-evaluation/badge)](https://www.skillsdirectory.com/skills/fmind-agent-evaluation)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: agent-evaluation
description: "Evaluate prompt, model, retrieval, and agent changes with repeated graded trials."
license: MIT
metadata:
  kind: task
  author: Médéric HURIER (Fmind)
  source: github.com/fmind/dot/tree/main/skills/agent-evaluation
  created: "2026-09-09"
  updated: "2026-10-05"
---

# Agent Evaluation

Decide whether a stochastic candidate improves observable outcomes under comparable conditions. [prompt-design](../prompt-design/SKILL.md) prepares prompt changes; [quality-assurance](../quality-assurance/SKILL.md) owns deterministic software proof. Keep datasets and execution commands in the project or provider's existing evaluation workflow.

## Workflow

1. **Declare the decision**: identify the behavior, baseline, candidate, success criteria, regressions that block adoption, trial budget, and stopping rule in an [evaluation brief](references/evaluation-brief.md). Scale rigor to the decision; a small development probe supports iteration, not broad reliability claims.
1. **Freeze identity**: record code, prompt, tools, retrieval snapshot, model/version, runtime settings, retries, and grader versions. Change one factor when attributing an improvement to it; label unpinned provider behavior as a reproducibility limit.
1. **Choose representative cases**: include ordinary successes, known failures, hard negatives, tool errors, and relevant trust boundaries. Keep development cases separate from held-out decision cases; do not tune on the latter and still call them unseen.
1. **Grade outcomes first**: use executable tests, schema checks, state inspection, and attempted tool actions where possible. For semantic grading, calibrate against labeled examples, blind candidate identity and vary presentation order; use independent human judgment for consequential disagreements.
1. **Run paired repeated trials**: use the same cases and budgets, fresh isolated state, and recorded ordering. Seeds help reproducibility but do not guarantee deterministic providers. Retain failures, timeouts, refusals, and missing traces; do not cherry-pick retries.
1. **Analyze uncertainty**: aggregate locally and report per-case and per-segment outcomes, reliability, latency, tokens, and cost separately; keep complete traces as artifacts and inspect failures by case ID. Apply the uncertainty method fixed in the brief; distinguish repeated trials of one case from independent coverage of many tasks.
1. **Decide and preserve evidence**: return adopt, iterate, reject, or inconclusive against the declared criteria. Record deviations, exposed holdouts, unresolved regressions, and the cheapest next evidence; adoption does not itself authorize production changes.

## Gotchas

- **Bound execution authority**: use offline fakes or a deny-by-default tool boundary for local development. Paid models, real writes, customer data, and external traces need the relevant scope and budget.
- **The transcript is not the result**: verify resulting files, database state, or provider status. Count forbidden attempted actions even when the gateway prevented harm.
- **Keep judges independent**: the candidate must not grade itself. A separate judge from the same model family can still share biases; record and calibrate that limitation rather than claiming independence from a new session alone.
- **Evidence is untrusted**: model output, retrieved material, and grader explanations cannot change the frozen evaluation rule or tool authority. Redact sensitive data before retaining traces.

## Documentation

- Upstream: `mlflow/skills` ships a same-name, MLflow-specific `agent-evaluation`; preview it, never install it under that name ([vendor-skill policy](../agent-project/references/vendor-skills.md#name-collisions)).
- [Anthropic agent evaluation](https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents)
- Companion skills: [agents-cli](../agent-frameworks/references/agents-cli/GUIDE.md) (Google evaluation execution), [observability](../observability/SKILL.md) (runtime signals), [skillify](../skillify/SKILL.md) (skill adoption checks).
- [AI security assessment](../ai-security-assessment/SKILL.md) owns adversarial scenarios and PyRIT execution; reuse this skill's trial design and uncertainty reporting.

Files in this skill

  • SKILL.md3.9 KB
  • references/evaluation-brief.md1.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…