animated-aws-arch
Pass
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection through its data processing pipeline.
- Ingestion points: The
scripts/gen_arch.pyscript reads a JSON specification file (referenced inSKILL.md) to generate SVG output. - Boundary markers: Absent. The script directly interpolates string values from the JSON input into the SVG XML structure without delimiters or warnings to ignore embedded instructions.
- Capability inventory: The skill instructions in
SKILL.mddirect the agent to execute a Python script and a headless browser (Google Chrome) for rendering and verification. The script performs local file reads and writes. - Sanitization: Absent. The generator script (
scripts/gen_arch.py) does not escape or sanitize text labels (e.g.,title,subtitle,label) before including them in the final SVG markup. This creates a vulnerability where a maliciously crafted specification could inject arbitrary SVG tags or scripts. - [COMMAND_EXECUTION]: The skill workflow involves instructions for the AI agent to execute local shell commands.
- The agent is instructed to run
python3 scripts/gen_arch.pyto render diagrams. - The agent is instructed to execute a headless Google Chrome command (e.g.,
"/Applications/Google Chrome.app/Contents/MacOS/Google Chrome" --headless ...) to verify the layout of the generated SVG. While these are part of the documented workflow, they expand the agent's active execution surface.
Audit Metadata