skills/grahama1970/agent-skills/argue/Gen Agent Trust Hub

argue

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs dynamic loading of a Python module from a path computed at runtime.
  • Evidence: In memory_integration.py, the code uses importlib.util.spec_from_file_location to load a taxonomy.py file from a relative sibling directory (../taxonomy/taxonomy.py).
  • [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection through the processing of user-supplied debate topics and persona-generated arguments.
  • Ingestion points: Untrusted data enters via the topic, positions, consensus, and strongest_arguments parameters in the learn_debate and recall_prior_debates functions in memory_integration.py.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands were found in the implementation to delimit this untrusted content.
  • Capability inventory: The skill is permitted to use high-privilege tools including Bash, Read, Write, and Task management as specified in SKILL.md.
  • Sanitization: There is no evidence of sanitization, escaping, or schema validation for the ingested strings before they are stored or used in memory recall operations.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — argue