skill-comply
Warn
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted Markdown files to generate compliance specifications and test scenarios via an LLM, creating a surface for indirect prompt injection.
- Ingestion points: The
scripts/spec_generator.pyandscripts/scenario_generator.pyfiles read the content of the user-provided target file and interpolate it directly into LLM prompt templates. - Boundary markers: The prompt templates in
prompts/spec_generator.mdandprompts/scenario_generator.mdlack explicit delimiters or instructions to ignore potential injections within the skill content. - Capability inventory: The skill can execute shell commands, read and write files, and invoke the Claude CLI agent.
- Sanitization: There is no validation or sanitization of the input file content before it is passed to the LLM.
- [COMMAND_EXECUTION]: The skill executes shell commands generated by an LLM based on untrusted input.
- In
scripts/runner.py, the_setup_sandboxfunction executessetup_commandsusingsubprocess.run(). - While restricted to a whitelist (
git,npm,pip,pip3,touch,mkdir,cp,mv,echo,chmod,unzip,tar), the arguments for these commands are not validated. Tools likepipandnpmcan be used to install malicious packages that execute code during installation, andchmodcan be used to alter file permissions within the sandbox. - [DYNAMIC_EXECUTION]: The skill dynamically generates and executes both shell commands and task prompts for a secondary agent session (
claude -p). A malicious input file could influence the generatedsetup_commandsor the scenariopromptto trigger unintended behaviors or exploit the testing environment.
Audit Metadata