tcm-meridian-inference
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The
tcm_api.pyscript utilizesimportlibto load local modules at runtime, which is restricted to internal skill files. - [COMMAND_EXECUTION]: The shell script
start_api.shis provided to manage the startup of the API service. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user-supplied measurement data, creating a potential surface for indirect prompt injection. 1. Ingestion points: Data is received via HTTP POST in
scripts/tcm_api.py. 2. Boundary markers: Delimiters are not used. 3. Capability inventory: The core logic inscripts/infer.pyis numeric and rule-based, with no access to high-risk system commands or file operations. 4. Sanitization: All measurement inputs are cast to floating-point numbers inscripts/infer.py, which prevents the execution of malicious text-based payloads.
Audit Metadata