phronesis
Warn
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill's extraction pipeline in
core/extraction/pipeline.pyperforms dynamic module loading. It modifies the Python path usingsys.path.insert(0, ...)with a path constructed from the user's home directory (Path.home() / "broomva" / "skills" / "bookkeeping" / "scripts") and then executesimport bookkeeping. This pattern of loading and executing code from a computed location outside the package's environment is a security concern if that local path is accessible to other processes. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources such as interview transcripts and ingested documents in
stages/intake.py. This data is subsequently interpolated into Jinja2 templates (e.g.,templates/use-case-dossier.md.j2,templates/maturity-report.md.j2) to produce engagement deliverables. The analysis identified the following evidence chain: - Ingestion points:
IntakeStage.log_interviewandIntakeStage.ingest_documentinstages/intake.pyreceive external content. - Boundary markers: The templates in the
templates/directory do not use delimiters or explicit warnings to instruct the AI to ignore instructions embedded in the external content. - Capability inventory: The skill has the capability to write to the engagement journal (
core/engagement.py) and render markdown files to the local disk (core/orchestrator.py). - Sanitization: No sanitization or filtering logic was found for the external content before it is processed by the agent or rendered into final reports.
Audit Metadata