ar-policy-builder

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted content from external documents (PDF, text) to generate formal logical rules.
  • Ingestion points: scripts/extract_rules_with_llm.py and scripts/build_from_document.py read document content via the --file CLI argument.
  • Boundary markers: The prompt templates in scripts/extract_rules_with_llm.py interpolate the source text directly into the prompt instructions without using distinct delimiters or XML tags to isolate the untrusted content.
  • Capability inventory: The skill uses boto3 to call Bedrock's logical reasoning and build APIs. A maliciously crafted document could contain instructions intended to override the extraction guidelines or generate incorrect/unsafe policy rules.
  • Sanitization: There is no evidence of input validation or content filtering performed on the source text before it is processed by the LLM.
  • [COMMAND_EXECUTION]: The skill includes several Python scripts designed to be executed via uv run. These scripts perform local file system reads and interact with AWS APIs. While these are necessary for the skill's primary function, they involve the execution of logic that handles external user-provided data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 07:07 PM