fix-llm-artifacts
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill uses finding descriptions to guide code modifications, creating an attack surface for malicious data in the input JSON files.
- Ingestion points: Ingests findings from
.beagle/llm-artifacts-review.jsonand overrides from.beagle/llm-artifacts-verification.json. - Boundary markers: Lacks explicit delimiters or instructions for the agent to ignore potentially malicious embedded instructions in the metadata fields.
- Capability inventory: The agent can write to the filesystem and execute various command-line utilities including linters and test suites.
- Sanitization: Validates finding IDs and file existence but does not sanitize the text content of the descriptions.
- [COMMAND_EXECUTION]: The skill runs multiple development and verification tools as part of its core logic.
- Evidence: Invokes
gitfor status and stashing;jqfor JSON manipulation; andruff,mypy,eslint,tsc,go, andpytestfor code verification. - [DYNAMIC_EXECUTION]: The skill executes a dynamically generated Python script for data validation.
- Evidence: Section 3 passes an inline Python script via a heredoc to the
python3interpreter to process, print, and lock IDs from the review JSON file for the anti-confabulation gate.
Audit Metadata