extract-python-environment-variables

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Script Execution: The skill executes a local Python utility (extract_env_vars.py) using uv run. This script performs the core logic of scanning files and applying refactors. It uses the Python ast module for static analysis, which is a robust and safe method for inspecting and modifying code structure without executing it.- File Modification: The skill modifies project files including .env.example, __init__.py, and pyproject.toml. These modifications are governed by specific safety rules (Rule 1 and Rule 2) mentioned in the documentation, such as preserving user-authored content and using atomic writing methods to ensure file integrity.- Indirect Prompt Injection Surface: As a code-scanning tool, the skill processes untrusted Python source code, which presents an attack surface for indirect prompt injection.
  • Ingestion points: The script reads and processes all .py files within the provided recipe directory, excluding common test and virtual environment folders.
  • Boundary markers: Extracted data is presented to the agent in markdown tables; there are no explicit instructions for the agent to ignore or delimit instructions that might be embedded in the scanned code.
  • Capability inventory: The skill has permissions to read from the filesystem and write modifications to project source code and configuration files.
  • Sanitization: The script includes sanitization logic, such as a strict regex (^[A-Z_][A-Z0-9_]*$) for environment variable names, which prevents certain types of injection through malformed variable names.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 05:53 AM
Security Audit — agent-trust-hub — extract-python-environment-variables