tor-procurement
Warn
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The Python scripts
tor_docx.pyandtor_respond.pymodify the search path (sys.path) at runtime to import theane_packagedependency. This resolution depends on theWORK_FOLDER_ROOTenvironment variable or directory hierarchy traversal to find the library location. - [COMMAND_EXECUTION]: The skill operates by executing local Python tools. In 'build' mode, the agent is instructed to duplicate and customize a generator script (
scripts/tor_docx.py) and then execute it to produce Word documents. - [DATA_EXPOSURE]: The script
scripts/tor_respond.pycontains a hardcoded Windows file path (C:\Users\AGasser\OneDrive\5 ANE CLAUDE work folder) which exposes details of the author's local file system structure in the codebase.
Audit Metadata