In Evaluator.collect_outputs(), workspace export and flag collection share the same try block. If workspace export raises, flag collection is skipped and verification can report "flag.txt not found" despite the flag could be readable in the container.
Q: Is this intentional? Workspace saving is optional, so collecting the flag separately seems reasonable to me. On the other hand, missing workspace files could make it harder to verify which vulnerability was used.
In Evaluator.collect_outputs(), workspace export and flag collection share the same
tryblock. If workspace export raises, flag collection is skipped and verification can report "flag.txt not found" despite the flag could be readable in the container.Q: Is this intentional? Workspace saving is optional, so collecting the flag separately seems reasonable to me. On the other hand, missing workspace files could make it harder to verify which vulnerability was used.