argue
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs dynamic loading of a Python module from a path computed at runtime.
- Evidence: In
memory_integration.py, the code usesimportlib.util.spec_from_file_locationto load ataxonomy.pyfile from a relative sibling directory (../taxonomy/taxonomy.py). - [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection through the processing of user-supplied debate topics and persona-generated arguments.
- Ingestion points: Untrusted data enters via the
topic,positions,consensus, andstrongest_argumentsparameters in thelearn_debateandrecall_prior_debatesfunctions inmemory_integration.py. - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands were found in the implementation to delimit this untrusted content.
- Capability inventory: The skill is permitted to use high-privilege tools including
Bash,Read,Write, andTaskmanagement as specified inSKILL.md. - Sanitization: There is no evidence of sanitization, escaping, or schema validation for the ingested strings before they are stored or used in memory recall operations.
Audit Metadata