infrastructure-compliance-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/dns_security_checker.py executes system commands using the subprocess module to perform DNS lookups via dig and nslookup tools. * Evidence: Function run_dig in scripts/dns_security_checker.py uses subprocess.run to call dig with user-supplied domain names. * Evidence: Function query_txt_records in scripts/dns_security_checker.py uses subprocess.run to call nslookup for TXT record queries. * Context: The script passes arguments as a list and does not use shell=True, which prevents shell command injection. These operations are essential for the skill's purpose of auditing DNS security settings.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process infrastructure configuration data from external JSON files, which could potentially contain malicious natural language instructions designed to influence the AI agent. * Ingestion points: The infra_audit_runner.py and access_control_auditor.py scripts load data from a user-specified path using the --config flag. * Boundary markers: The scripts do not implement specific boundary markers or warnings to the AI agent to ignore natural language instructions within the processed data. * Capability inventory: The skill has the ability to read local files, execute system commands for network reconnaissance (DNS), and output audit reports that the agent will consume. * Sanitization: There is no evidence of sanitization or filtering applied to the configuration data to remove potentially manipulative content before it is included in the generated audit reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 02:11 AM
Security Audit — agent-trust-hub — infrastructure-compliance-auditor