fix-llm-artifacts

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill uses finding descriptions to guide code modifications, creating an attack surface for malicious data in the input JSON files.
  • Ingestion points: Ingests findings from .beagle/llm-artifacts-review.json and overrides from .beagle/llm-artifacts-verification.json.
  • Boundary markers: Lacks explicit delimiters or instructions for the agent to ignore potentially malicious embedded instructions in the metadata fields.
  • Capability inventory: The agent can write to the filesystem and execute various command-line utilities including linters and test suites.
  • Sanitization: Validates finding IDs and file existence but does not sanitize the text content of the descriptions.
  • [COMMAND_EXECUTION]: The skill runs multiple development and verification tools as part of its core logic.
  • Evidence: Invokes git for status and stashing; jq for JSON manipulation; and ruff, mypy, eslint, tsc, go, and pytest for code verification.
  • [DYNAMIC_EXECUTION]: The skill executes a dynamically generated Python script for data validation.
  • Evidence: Section 3 passes an inline Python script via a heredoc to the python3 interpreter to process, print, and lock IDs from the review JSON file for the anti-confabulation gate.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:17 AM
Security Audit — agent-trust-hub — fix-llm-artifacts