skills/broomva/skills/phronesis/Gen Agent Trust Hub

phronesis

Warn

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill's extraction pipeline in core/extraction/pipeline.py performs dynamic module loading. It modifies the Python path using sys.path.insert(0, ...) with a path constructed from the user's home directory (Path.home() / "broomva" / "skills" / "bookkeeping" / "scripts") and then executes import bookkeeping. This pattern of loading and executing code from a computed location outside the package's environment is a security concern if that local path is accessible to other processes.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources such as interview transcripts and ingested documents in stages/intake.py. This data is subsequently interpolated into Jinja2 templates (e.g., templates/use-case-dossier.md.j2, templates/maturity-report.md.j2) to produce engagement deliverables. The analysis identified the following evidence chain:
  • Ingestion points: IntakeStage.log_interview and IntakeStage.ingest_document in stages/intake.py receive external content.
  • Boundary markers: The templates in the templates/ directory do not use delimiters or explicit warnings to instruct the AI to ignore instructions embedded in the external content.
  • Capability inventory: The skill has the capability to write to the engagement journal (core/engagement.py) and render markdown files to the local disk (core/orchestrator.py).
  • Sanitization: No sanitization or filtering logic was found for the external content before it is processed by the agent or rendered into final reports.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 7, 2026, 03:25 PM
Security Audit — agent-trust-hub — phronesis