ar-runtime-validator

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (questions and answers) and interpolates them into prompt templates for LLM rewriting.
  • Ingestion points: The --question and --answer arguments in scripts/rewrite_loop.py and scripts/validate_response.py.
  • Boundary markers: Absent. The templates in references/rewrite-templates.md and scripts/rewrite_loop.py do not use distinctive delimiters to separate instructions from untrusted data.
  • Capability inventory: The skill uses the boto3 library to interact with Amazon Bedrock APIs (apply_guardrail, converse) in scripts/rewrite_loop.py and scripts/validate_response.py.
  • Sanitization: Absent. No escaping or validation is performed on input strings before they are processed by the LLM.
  • [COMMAND_EXECUTION]: The documentation provides examples of how to execute the provided Python scripts using the uv tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 07:07 PM