skill-comply

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted Markdown files to generate compliance specifications and test scenarios via an LLM, creating a surface for indirect prompt injection.
  • Ingestion points: The scripts/spec_generator.py and scripts/scenario_generator.py files read the content of the user-provided target file and interpolate it directly into LLM prompt templates.
  • Boundary markers: The prompt templates in prompts/spec_generator.md and prompts/scenario_generator.md lack explicit delimiters or instructions to ignore potential injections within the skill content.
  • Capability inventory: The skill can execute shell commands, read and write files, and invoke the Claude CLI agent.
  • Sanitization: There is no validation or sanitization of the input file content before it is passed to the LLM.
  • [COMMAND_EXECUTION]: The skill executes shell commands generated by an LLM based on untrusted input.
  • In scripts/runner.py, the _setup_sandbox function executes setup_commands using subprocess.run().
  • While restricted to a whitelist (git, npm, pip, pip3, touch, mkdir, cp, mv, echo, chmod, unzip, tar), the arguments for these commands are not validated. Tools like pip and npm can be used to install malicious packages that execute code during installation, and chmod can be used to alter file permissions within the sandbox.
  • [DYNAMIC_EXECUTION]: The skill dynamically generates and executes both shell commands and task prompts for a secondary agent session (claude -p). A malicious input file could influence the generated setup_commands or the scenario prompt to trigger unintended behaviors or exploit the testing environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — skill-comply