skill-comply

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands that are dynamically generated by an LLM based on user-provided input files. In scripts/runner.py, the run_scenario function executes setup_commands using subprocess.run. These commands originate from the scenario_generator.py process, which uses the content of the skill being tested to produce them. There is no validation to ensure these commands are safe or restricted to the sandbox directory.
  • [PROMPT_INJECTION]: The skill is vulnerable to Indirect Prompt Injection (Category 8). It reads external Markdown files (skills/rules) and interpolates their raw content into multiple prompts used for generating compliance specifications and test scenarios. A malicious file could include instructions that hijack the scenario generation process or influence the behavior of the agent during execution.
  • Ingestion points: User-specified skill files processed in scripts/run.py and passed to generators.
  • Boundary markers: Prompts in prompts/spec_generator.md and prompts/scenario_generator.md use basic triple-dash delimiters, which are insufficient to prevent injection from adversarial content.
  • Capability inventory: The skill uses subprocess.run to execute host commands and triggers claude -p with a broad set of tools including Bash, Write, and Edit.
  • Sanitization: There is no sanitization or verification of the LLM-generated commands or the input skill content before it is used to drive system actions.
  • [REMOTE_CODE_EXECUTION]: The run_scenario function in scripts/runner.py invokes claude -p with highly capable tools (Bash, Write, Edit, Glob, Grep) enabled. Since the prompt passed to this command is generated from untrusted skill content, a compromised prompt could lead to the AI agent executing arbitrary code on the user's machine.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — skill-comply