skill-comply
Fail
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Host-level shell command execution of untrusted content. In
scripts/runner.py, the_setup_sandboxfunction executes a series ofsetup_commandsusingsubprocess.run. These commands are dynamically generated by an LLM inscripts/scenario_generator.pybased on the content of an external skill or rule file provided as input. Since these commands run on the host system (within/tmp), they pose a direct risk of arbitrary code execution. - [PROMPT_INJECTION]: Vulnerability to indirect prompt injection. The workflow in
scripts/scenario_generator.pyingests untrusted data from a user-provided file and passes it to an LLM to generate execution instructions. An attacker can craft a 'skill' file that includes instructions to bypass safety filters and generate malicioussetup_commands(e.g., to exfiltrate environment variables, access sensitive configuration files like.aws/credentials, or delete data). - Ingestion points: Target file content is read in
scripts/run.pyand interpolated into prompts inscripts/spec_generator.pyandscripts/scenario_generator.py. - Boundary markers: Only simple horizontal rules (
---) are used to delimit external content in LLM prompts, which provides no protection against adversarial instructions. - Capability inventory:
subprocess.runis used extensively throughout the codebase to execute host-level shell commands and theclaudeCLI. - Sanitization: No validation is performed on the LLM-generated commands before execution. While
shlex.splitis used, it only prevents shell parsing issues and does not validate the command's intent or safety. - [COMMAND_EXECUTION]: Potential for CLI argument or prompt injection. The skill uses
subprocess.runto call theclaudeCLI across multiple scripts with prompts containing unvalidated data derived from external files. This increases the risk of unexpected CLI behavior or exploitation if the injected content is designed to manipulate the underlying tool's logic.
Recommendations
- AI detected serious security threats
Audit Metadata