skills/broomva/skills/bookkeeping/Gen Agent Trust Hub

bookkeeping

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and process data from external, untrusted sources such as web clips, social media logs, and conversation transcripts. This creates a significant surface for indirect prompt injection attacks.
  • Ingestion points: Content is ingested through the ingest and run commands in scripts/bookkeeping.py, which normalize raw sources into the entity graph.
  • Boundary markers: Although the skill uses structured YAML and markdown, the LLM scoring rubric and judge prompt do not include explicit 'ignore embedded instructions' warnings for the content being evaluated.
  • Capability inventory: The skill has the ability to write files to the research/ directory and execute shell commands via subprocess. A successful injection could influence which data is promoted or what shell commands are proposed during maintenance.
  • Sanitization: The skill performs validation of slug shapes and strips non-printable control characters (e.g., NUL bytes) to prevent filesystem corruption.
  • [COMMAND_EXECUTION]: The skill utilizes subprocess.run for operational automation, which is an expected but powerful capability.
  • Evidence: Static analysis and test files (e.g., tests/test_render_cli.py, tests/test_temporal_revision_metadata.py) show the skill executes its own subcommands and system tools like git via the shell. While restricted to its intended purpose, this represents a capability that could be leveraged by an attacker if combined with an injection vulnerability.
  • [DYNAMIC_EXECUTION]: The skill's test infrastructure uses dynamic code loading to verify integration with other local tools.
  • Evidence: tests/test_index.py uses importlib.util to dynamically load and execute local scripts (e.g., kg.py) based on computed filesystem paths. This is limited to the local environment and intended for development testing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:13 PM
Security Audit — agent-trust-hub — bookkeeping