skill-comply

Fail

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Host-level shell command execution of untrusted content. In scripts/runner.py, the _setup_sandbox function executes a series of setup_commands using subprocess.run. These commands are dynamically generated by an LLM in scripts/scenario_generator.py based on the content of an external skill or rule file provided as input. Since these commands run on the host system (within /tmp), they pose a direct risk of arbitrary code execution.
  • [PROMPT_INJECTION]: Vulnerability to indirect prompt injection. The workflow in scripts/scenario_generator.py ingests untrusted data from a user-provided file and passes it to an LLM to generate execution instructions. An attacker can craft a 'skill' file that includes instructions to bypass safety filters and generate malicious setup_commands (e.g., to exfiltrate environment variables, access sensitive configuration files like .aws/credentials, or delete data).
  • Ingestion points: Target file content is read in scripts/run.py and interpolated into prompts in scripts/spec_generator.py and scripts/scenario_generator.py.
  • Boundary markers: Only simple horizontal rules (---) are used to delimit external content in LLM prompts, which provides no protection against adversarial instructions.
  • Capability inventory: subprocess.run is used extensively throughout the codebase to execute host-level shell commands and the claude CLI.
  • Sanitization: No validation is performed on the LLM-generated commands before execution. While shlex.split is used, it only prevents shell parsing issues and does not validate the command's intent or safety.
  • [COMMAND_EXECUTION]: Potential for CLI argument or prompt injection. The skill uses subprocess.run to call the claude CLI across multiple scripts with prompts containing unvalidated data derived from external files. This increases the risk of unexpected CLI behavior or exploitation if the injected content is designed to manipulate the underlying tool's logic.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 1, 2026, 11:09 AM
Security Audit — agent-trust-hub — skill-comply