tor-procurement

Warn

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The Python scripts tor_docx.py and tor_respond.py modify the search path (sys.path) at runtime to import the ane_package dependency. This resolution depends on the WORK_FOLDER_ROOT environment variable or directory hierarchy traversal to find the library location.
  • [COMMAND_EXECUTION]: The skill operates by executing local Python tools. In 'build' mode, the agent is instructed to duplicate and customize a generator script (scripts/tor_docx.py) and then execute it to produce Word documents.
  • [DATA_EXPOSURE]: The script scripts/tor_respond.py contains a hardcoded Windows file path (C:\Users\AGasser\OneDrive\5 ANE CLAUDE work folder) which exposes details of the author's local file system structure in the codebase.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 5, 2026, 07:54 PM
Security Audit — agent-trust-hub — tor-procurement