How Reproducible Are Evaluation Conclusions? A Self-Audit of LLM-Inferred Prompt Structure
Organizations: Skelf Research
Abstract
Evaluations of LLM systems routinely average over small prompt sets and report models as a ranked table. We ask how much confidence such a table deserves, using LLM-based prompt-structure inference as the case study: eight open model variants across five families and 8B to 675B parameters, caching disabled, 293 raw intermediate representations persisted. The measured phenomenon is unstable to begin with. Identical calls do not reliably recover identical structure, with mean node-set Jaccard from 0.39 to 0.96 and 72% of prompt-model cells never node-set-perfect. Auditing the evaluation weakens its conclusions further, and this is our main contribution. Under a joint cluster bootstrap over prompts, only the bottom of the ranking is firm: the two least reproducible models hold rank in 99% and 86% of replicates, the middle four in 27% to 48%, and the top two in 68% each, so the table identifies the worst model reliably but does not reliably identify the best. Two equally defensible rules for merging repeated campaigns change four of eight rows and move the study-wide headline by 7 percentage points. Checking the inferred structure against ground-truth annotations shows reproducibility cannot be read as accuracy. And four of the eight endpoints were withdrawn within ten weeks of measurement, so the study as specified can no longer be run. Small-sample LLM evaluations can therefore look far more definitive than their evidence supports. We recommend reporting rank stability, per-cell provenance, executed sensitivity comparisons, raw per-run outputs, and a measurement date alongside any ranking.
Figures & tables
| Model | Family | Jaccard [95% CI] | ID-stab [95% CI] | Perfect | Rank held | |
| minimax-m2.1 | MiniMax | 3 | 0.96 [0.89, 1.00] | 0.96 [0.89, 1.00] | 2/3 | 68% |
| gemma3:12b | 22 | 0.94 [0.90, 0.98] | 0.92 [0.85, 0.98] | 15/22 | 68% | |
| mistral-large-3:675b | Mistral | 19 | 0.80 [0.73, 0.86] | 0.71 [0.62, 0.80] | 3/19 | 48% |
| ministral-3:8b | Mistral | 19 | 0.77 [0.66, 0.87] | 0.71 [0.57, 0.83] | 6/19 | 27% |
| gpt-oss:20b | OpenAI-style | 20 | 0.76 [0.65, 0.85] | 0.69 [0.56, 0.80] | 4/20 | 47% |
| minimax-m2.7 | MiniMax | 6 | 0.70 [0.47, 0.89] | 0.68 [0.44, 0.89] | 2/6 | 48% |
| Claim or assumption | Audit | Outcome |
|---|---|---|
| gpt-oss:120b is the least reproducible model | joint cluster bootstrap (§ 5 ) | Holds. Stays last in 99% of replicates |
| minimax-m2.1 is the most reproducible model | joint cluster bootstrap (§ 5 ) | Not supported. Holds rank in 68%; which of the top two leads is undetermined |
| The reported ranking is robust to campaign-merging choices | alternative merge rule (§ 5 ) | Sensitive. Four of eight rows change; headline moves 7.1 points |
| Repeated inference stabilises after runs | tolerance specification (Appendix F ) | Specification-dependent. 80 vs 50 of 98 cells under two readings of one flag |
| DeepSeek and Zhipu are structurally inaccessible | harness audit (§ 7 ) | Withdrawn. Instrument is the leading candidate; cause unresolved |
| A stable IR is a correct IR | ground-truth annotations (§ 6 ) | Not supported. The two orderings diverge |
Appendix figures & tables1 asset
Supplementary material from the paper’s appendix.
Appendix
| Model | Role in the study | Status on 2026-08-17 |
| gpt-oss:20b | Table 1 | available |
| gpt-oss:120b | Table 1 | available |
| mistral-large-3:675b | Table 1 | available |
| minimax-m2.7 | Table 1 | available |
| gemma3:12b | Table 1 | retired 2026-07-15 |
| ministral-3:8b | Table 1 | retired 2026-07-15 |