skill-comply
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands that are dynamically generated by an LLM based on user-provided input files. In
scripts/runner.py, therun_scenariofunction executessetup_commandsusingsubprocess.run. These commands originate from thescenario_generator.pyprocess, which uses the content of the skill being tested to produce them. There is no validation to ensure these commands are safe or restricted to the sandbox directory. - [PROMPT_INJECTION]: The skill is vulnerable to Indirect Prompt Injection (Category 8). It reads external Markdown files (skills/rules) and interpolates their raw content into multiple prompts used for generating compliance specifications and test scenarios. A malicious file could include instructions that hijack the scenario generation process or influence the behavior of the agent during execution.
- Ingestion points: User-specified skill files processed in
scripts/run.pyand passed to generators. - Boundary markers: Prompts in
prompts/spec_generator.mdandprompts/scenario_generator.mduse basic triple-dash delimiters, which are insufficient to prevent injection from adversarial content. - Capability inventory: The skill uses
subprocess.runto execute host commands and triggersclaude -pwith a broad set of tools includingBash,Write, andEdit. - Sanitization: There is no sanitization or verification of the LLM-generated commands or the input skill content before it is used to drive system actions.
- [REMOTE_CODE_EXECUTION]: The
run_scenariofunction inscripts/runner.pyinvokesclaude -pwith highly capable tools (Bash,Write,Edit,Glob,Grep) enabled. Since the prompt passed to this command is generated from untrusted skill content, a compromised prompt could lead to the AI agent executing arbitrary code on the user's machine.
Audit Metadata